ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts
ConsentFix is a new social engineering attack variant targeting Microsoft 365 accounts by tricking users into granting OAuth access tokens to attackers. The attack involves convincing users to authenticate and perform specific browser actions that leak session tokens, enabling attackers to access corporate email, documents, and cloud services without stealing passwords. This technique bypasses multi-factor authentication and can lead to significant data exposure and lateral movement within corporate environments. The attack is facilitated by phishing emails linking to fake file-sharing sites and detailed public guides that lower the barrier for attackers. Organizations face risks including compromised email, phishing from legitimate accounts, data exfiltration, and malware uploads. Mitigations focus on mail gateway security and employee awareness training. No specific software versions are affected as this targets user behavior and OAuth flows rather than a software vulnerability.
AI Analysis
Technical Summary
ConsentFix is a newly identified variation of the ClickFix social engineering attack that compromises Microsoft 365 accounts by exploiting OAuth token granting processes. Attackers send phishing emails linking to fake file-sharing sites that prompt users to authenticate with their Microsoft 365 accounts and perform a sequence of browser actions, including dragging an OAuth token URL into a drop zone controlled by the attacker. This grants attackers access to the victim's Microsoft 365 session without requiring password theft or bypassing multi-factor authentication. The attack can expose corporate email, Teams, OneDrive, SharePoint, and other services depending on the organization's subscription and privileges. Publicly available attack blueprints and tutorials facilitate widespread adoption of this technique. Defenses include robust email gateway security and ongoing user training to recognize and resist social engineering tactics.
Potential Impact
Successful exploitation results in unauthorized access to Microsoft 365 accounts, allowing attackers to read and send corporate emails, access Teams communications, exfiltrate or tamper with documents on OneDrive and SharePoint, and potentially move laterally within the corporate network. This can lead to data breaches, business email compromise, internal phishing, malware deployment, and broader organizational compromise. The attack bypasses password theft and multi-factor authentication, increasing its effectiveness against standard security controls.
Mitigation Recommendations
No official patch is applicable as this is a social engineering attack exploiting OAuth flows. Organizations should deploy strong email gateway security solutions to reduce phishing email delivery. Regular cybersecurity awareness training is critical to educate employees about the ConsentFix technique and similar social engineering tactics. Blocking specific browser actions is insufficient due to attacker adaptability. Monitoring and restricting OAuth app permissions within Microsoft 365 can also help reduce risk. Organizations should incorporate this threat into their security awareness programs and incident response plans.
ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts
Description
ConsentFix is a new social engineering attack variant targeting Microsoft 365 accounts by tricking users into granting OAuth access tokens to attackers. The attack involves convincing users to authenticate and perform specific browser actions that leak session tokens, enabling attackers to access corporate email, documents, and cloud services without stealing passwords. This technique bypasses multi-factor authentication and can lead to significant data exposure and lateral movement within corporate environments. The attack is facilitated by phishing emails linking to fake file-sharing sites and detailed public guides that lower the barrier for attackers. Organizations face risks including compromised email, phishing from legitimate accounts, data exfiltration, and malware uploads. Mitigations focus on mail gateway security and employee awareness training. No specific software versions are affected as this targets user behavior and OAuth flows rather than a software vulnerability.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ConsentFix is a newly identified variation of the ClickFix social engineering attack that compromises Microsoft 365 accounts by exploiting OAuth token granting processes. Attackers send phishing emails linking to fake file-sharing sites that prompt users to authenticate with their Microsoft 365 accounts and perform a sequence of browser actions, including dragging an OAuth token URL into a drop zone controlled by the attacker. This grants attackers access to the victim's Microsoft 365 session without requiring password theft or bypassing multi-factor authentication. The attack can expose corporate email, Teams, OneDrive, SharePoint, and other services depending on the organization's subscription and privileges. Publicly available attack blueprints and tutorials facilitate widespread adoption of this technique. Defenses include robust email gateway security and ongoing user training to recognize and resist social engineering tactics.
Potential Impact
Successful exploitation results in unauthorized access to Microsoft 365 accounts, allowing attackers to read and send corporate emails, access Teams communications, exfiltrate or tamper with documents on OneDrive and SharePoint, and potentially move laterally within the corporate network. This can lead to data breaches, business email compromise, internal phishing, malware deployment, and broader organizational compromise. The attack bypasses password theft and multi-factor authentication, increasing its effectiveness against standard security controls.
Mitigation Recommendations
No official patch is applicable as this is a social engineering attack exploiting OAuth flows. Organizations should deploy strong email gateway security solutions to reduce phishing email delivery. Regular cybersecurity awareness training is critical to educate employees about the ConsentFix technique and similar social engineering tactics. Blocking specific browser actions is insufficient due to attacker adaptability. Monitoring and restricting OAuth app permissions within Microsoft 365 can also help reduce risk. Organizations should incorporate this threat into their security awareness programs and incident response plans.
Technical Details
- Article Source
- {"url":"https://www.kaspersky.com/blog/consentfix-microsoft-365-account-hijacking/56155/","fetched":true,"fetchedAt":"2026-07-21T15:34:37.955Z","wordCount":1230}
Threat ID: 6a5f918d2a4a8d5989579eda
Added to database: 07/21/2026, 15:34:37 UTC
Last enriched: 07/21/2026, 15:34:46 UTC
Last updated: 07/21/2026, 16:51:40 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.