ConsentFix — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
May 2, 2026
Last Seen
July 4, 2026

Related Threat Clusters

  • Automated ConsentFix v3 Attack Targets Microsoft Azure Accounts

    A new attack technique named ConsentFix v3 has emerged, automating the hijacking of Microsoft Azure accounts through sophisticated phishing methods. This attack builds on previous versions by enhancing automation and…

    2 articles · Updated May 4, 2026
  • ConsentFix and ClickFix: Rapid Hijacking of Microsoft 365 Accounts

    Cybercriminals are exploiting two attack methods, ConsentFix and ClickFix, to hijack Microsoft 365 accounts in as little as three seconds. These attacks leverage users' habitual online behaviors, such as dragging links…

    2 articles · Updated July 4, 2026
  • Malware Spreads via Verified Ads on X Targeting Mac Users

    A ClickFix-style malware campaign was detected spreading through a sponsored ad on X, originating from a verified account. The ad masqueraded as the legitimate Mac app DynamicLake, leading users to a malicious domain,…

    3 articles · Updated July 4, 2026

Recent Intelligence Reports

  • Verified X Sponsored Ad Spreads Mac Malware While ConsentFix Hijacks Microsoft 365 Accounts — Gbhackers · July 4, 2026
  • ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds — Oodaloop · July 4, 2026
  • ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds — Bleepingcomputer · July 2, 2026
  • ConsentFix v3 attacks target Azure with automated OAuth abuse — Bleepingcomputer · May 2, 2026

CVSS v3.1 Breakdown