ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts
ID: d5a482b0-5712-5dfe-9931-2a0e93e6e58b
STIX ID: report--d5a482b0-5712-5dfe-9931-2a0e93e6e58b
Feed Name: Security Boulevard
ConsentFix v3 automates an OAuth authorization-code phishing technique against Azure/Microsoft 365: attackers verify Azure tenant presence, harvest employee data for personalized phishing, host convincing pages via Cloudflare/DocSend, and use Pipedream as a webhook to exchange captured authorization codes for refresh tokens—thereby hijacking accounts despite MFA. The report highlights scale and stealth because the flow uses legitimate Microsoft apps and first-party consents, and recommends mitigations including token binding, anomalous OAuth detection and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
