Automated ConsentFix v3 Attack Targets Microsoft Azure Accounts

Automated ConsentFix v3 Attack Targets Microsoft Azure Accounts

First seen 5 May 2026, 00:06 UTC BleepingcomputerScworld 87% similarity 69.5

Article Content

Browse articles
ThreatCluster

A new attack technique named ConsentFix v3 has emerged, automating the hijacking of Microsoft Azure accounts through sophisticated phishing methods. This attack builds on previous versions by enhancing automation and scalability to bypass security measures. It utilizes social engineering and exploits the OAuth2 authorization code flow to gain unauthorized access to user accounts. Attackers first identify valid tenant IDs and gather employee details for impersonation. They create multiple accounts across various services, leveraging Pipedream as a central tool for automation. The phishing scheme involves a page hosted on Cloudflare that mimics the Microsoft/Azure interface, tricking victims into pasting a localhost URL containing an OAuth authorization code. Once the code is captured, it is exchanged for tokens that grant access to compromised environments. The full impact of this attack is still being assessed, and mitigation strategies are recommended. As of now, it is unclear if this variant has gained widespread adoption among cybercriminals.

Key Points: • ConsentFix v3 automates Microsoft Azure account hijacking using OAuth2 exploitation. • Attackers impersonate employees by gathering details and creating multiple service accounts. • Mitigation strategies include token binding and behavioral detection rules.

ThreatCluster AI

Timeline

2025-12-01
ConsentFix v1 introduced by Push Security
2026-01-10
ConsentFix v2 developed by John Hammond
2026-05-02
ConsentFix v3 reported by Bleeping Computer
2026-05-04
ConsentFix v3 covered by Scworld

Community

Browse all →