ConsentFix: a New ClickFix Variation for Compromising Microsoft 365 Accounts
Researchers have identified ConsentFix, a new variation of the ClickFix social engineering attack that enables cybercriminals to hijack Microsoft 365 accounts via OAuth tokens without stealing passwords. By tricking users into dragging a session token URL into an attacker-controlled page during a fake authentication process, attackers gain access to corporate email, documents, Teams, and other cloud services, facilitating data exfiltration and lateral movement within organizations. The widespread availability of ConsentFix attack blueprints increases the risk of such intrusions, highlighting the need for robust email security solutions and employee awareness training.
https://www.kaspersky.com/blog/consentfix-microsoft-365-account-hijacking/56155/















