In
December, the Push Security research team discovered and blocked a brand new attack technique that we coined
ConsentFix.
This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts.
ConsentFix is an attack
technique that prompts the victim to share an OAuth authorization code with an attacker via a phishing page.
The attacker then enters this code into a target application on their own device in order to complete the authorization handshake and take over the account.
By hijacking OAuth, attackers can effectively
bypass identity-layer controls like passwords and MFA — even phishing resistant authentication methods like passkeys have no impact on this attack, because it sidesteps the authentication process altogether.
ConsentFix is an OAuth phishing technique abusing browser-based authorization flows to hijack Microsoft accounts. Push Security shares new insights from continued tracking, community research, and evolving attacker techniques.
www.bleepingcomputer.com