ConsentFix phishing trick steals Microsoft 365 session tokens through fake OAuth sign-in steps

Attackers are using a new phishing technique called ConsentFix to hijack Microsoft 365 accounts by tricking users into completing what looks like a normal sign-in step. The lure often arrives through services such as Dropbox or DocSend and asks the victim to drag a localhost callback link into the browser during a Microsoft OAuth consent flow; doing so exposes OAuth session tokens, giving attackers access to email and other Microsoft 365 services without needing the user's password and effectively bypassing multi-factor authentication for that session. The article also says a full how-to guide, code, screenshots, and a video tutorial were posted on a Russian cybercrime forum in March 2026.
Why it matters: Microsoft 365 users and organizations can lose account access in seconds even when users do not type passwords into a fake page. Defenders should review OAuth app-consent controls, train users about drag-and-drop and fake verification prompts, and monitor for suspicious token issuance and cloud-session abuse.

Sources

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Sponsored by Huntress Labs 2026.07.02 100% relevant
This article establishes a distinct, named attack pattern focused on Microsoft 365 OAuth consent-flow abuse and session-token theft, rather than updating an already tracked incident or campaign in the list.
← Back to all stories