logo

New 'CoPhish' technique wraps OAuth phishing in Microsoft Copilot

ID: 792d0676-a66e-5898-b6cf-f5aa8e753f8c

STIX ID: report--792d0676-a66e-5898-b6cf-f5aa8e753f8c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-25

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

A new phishing technique called CoPhish leverages Microsoft Copilot Studio agents and their demo websites to display legitimate-looking OAuth consent/login flows on Microsoft domains, tricking users—including administrators—into approving malicious applications and exposing session/access tokens to attackers; Datadog details the attack flow and mitigations while Microsoft says it will address the issue in future updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.