logo

ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts

ID: d5a482b0-5712-5dfe-9931-2a0e93e6e58b

STIX ID: report--d5a482b0-5712-5dfe-9931-2a0e93e6e58b

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-05-03

Date Updated: 2026-05-03

Author: Evan Rowe

...
...

ConsentFix v3 automates an OAuth authorization-code phishing technique against Azure/Microsoft 365: attackers verify Azure tenant presence, harvest employee data for personalized phishing, host convincing pages via Cloudflare/DocSend, and use Pipedream as a webhook to exchange captured authorization codes for refresh tokens—thereby hijacking accounts despite MFA. The report highlights scale and stealth because the flow uses legitimate Microsoft apps and first-party consents, and recommends mitigations including token binding, anomalous OAuth detection and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.