New Phishing Tactics Exploit OAuth Tokens in Microsoft 365 Accounts
A sophisticated phishing campaign, dubbed ConsentFix, is targeting Microsoft 365 users by exploiting trusted platforms like Dropbox and DocSend to bypass security measures. Attackers send seemingly legitimate, password-protected lures that evade antivirus detection. Once opened, victims are tricked into dragging a localhost callback link into their browser or executing keyboard shortcuts (e.g., Windows key + R, Ctrl+V), unknowingly handing over OAuth tokens that grant full account access without requiring passwords or multi-factor authentication (MFA).
The attack, first documented on a Russian cybercrime forum in early 2026, was shared as a step-by-step guide complete with code, infrastructure screenshots, and a video tutorial. This "playbook" lowers the barrier for entry, enabling even low-skilled threat actors to launch high-impact attacks. The campaign leverages free services like Cloudflare Pages and Pipedream webhooks to host malicious infrastructure, while LinkedIn and ZoomInfo data is used to tailor phishing lures to specific targets.
Why It Works
ConsentFix exploits routine user behavior, such as clicking through OAuth consent prompts or following familiar sign-in flows. Unlike traditional phishing, victims don’t enter credentials into fake forms instead, they complete what appears to be a legitimate authentication process, inadvertently surrendering session tokens. The attack is fast (under three seconds) and leaves minimal traces, though defenders can detect anomalies like suspicious PowerShell activity or unusual login locations.
Impact
Once compromised, attackers gain access to email, OneDrive, Teams, and other Microsoft 365 resources, enabling data theft, lateral movement, or further phishing campaigns. The technique has evolved from earlier variants like ClickFix, which relied on similar social engineering tactics but with even less technical friction.
The campaign highlights a broader trend: cybercrime as a service (CaaS), where attack methods are packaged and distributed with step-by-step instructions, accelerating the spread of identity-based threats.
Source: https://www.huntress.com/blog/hacker-tactics-2026-dark-web-playbook
Dropbox DocSend cybersecurity rating report: https://www.rankiteo.com/company/docsend
Dropbox cybersecurity rating report: https://www.rankiteo.com/company/Dropbox
"id": "DOCDRO1782743043",
"linkid": "docsend, Dropbox",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'type': 'Organization'}],
'attack_vector': 'OAuth token exploitation, social engineering',
'data_breach': {'data_exfiltration': 'Possible',
'personally_identifiable_information': 'Possible',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'OAuth tokens, Microsoft 365 '
'resources (email, OneDrive, '
'Teams)'},
'date_publicly_disclosed': '2026-01',
'description': 'A sophisticated phishing campaign, dubbed ConsentFix, is '
'targeting Microsoft 365 users by exploiting trusted platforms '
'like Dropbox and DocSend to bypass security measures. '
'Attackers send seemingly legitimate, password-protected lures '
'that evade antivirus detection. Once opened, victims are '
'tricked into dragging a localhost callback link into their '
'browser or executing keyboard shortcuts, unknowingly handing '
'over OAuth tokens that grant full account access without '
'requiring passwords or multi-factor authentication (MFA).',
'impact': {'data_compromised': 'Email, OneDrive, Teams, and other Microsoft '
'365 resources',
'identity_theft_risk': 'High',
'operational_impact': 'Data theft, lateral movement, further '
'phishing campaigns',
'systems_affected': 'Microsoft 365 accounts'},
'initial_access_broker': {'backdoors_established': 'OAuth tokens',
'entry_point': 'Phishing lures via Dropbox, DocSend',
'high_value_targets': 'Microsoft 365 users'},
'lessons_learned': 'Exploits routine user behavior and trusted platforms to '
'bypass security measures. Attack methods are increasingly '
'packaged and distributed as cybercrime-as-a-service '
'(CaaS).',
'motivation': 'Data theft, lateral movement, further phishing campaigns',
'post_incident_analysis': {'corrective_actions': 'Enhanced monitoring, user '
'education, and detection of '
'anomalous activities',
'root_causes': 'Exploitation of OAuth consent '
'prompts, social engineering, and '
'user behavior'},
'recommendations': 'Enhance monitoring for suspicious PowerShell activity or '
'unusual login locations. Educate users on OAuth consent '
'prompt risks and social engineering tactics.',
'references': [{'source': 'Russian cybercrime forum'}],
'response': {'enhanced_monitoring': 'Detection of suspicious PowerShell '
'activity or unusual login locations'},
'threat_actor': 'Russian cybercrime forum actors',
'title': 'ConsentFix Phishing Campaign Exploiting OAuth Tokens in Microsoft '
'365 Accounts',
'type': 'Phishing',
'vulnerability_exploited': 'OAuth consent prompts, user behavior'}