ConsentFix v3 attacks target Azure with automated OAuth abuse
ID: d0c28264-6b42-5058-af7f-646967eb2c48
STIX ID: report--d0c28264-6b42-5058-af7f-646967eb2c48
Feed Name: Bleeping Computer
ConsentFix v3 is an automated OAuth-abuse campaign targeting Microsoft Azure environments: attackers enumerate tenants and employees, host convincing phishing pages (Cloudflare Pages) that initiate a real Microsoft OAuth flow, trick victims into returning a localhost authorization code (paste/drag-and-drop), forward that code to a Pipedream webhook which immediately redeems it for tokens, and then use stolen tokens (imported into tools like Specter Portal) to access email, files, and other resources. The report details reconnaissance and infrastructure choices (DocSend, Hunter.io, Tutanota), describes automation and scalability improvements over prior variants, and outlines mitigations such as token binding, app auth restrictions, and behavioral detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
