Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Cybercriminals

ConsentFix Attack: New Phishing Bypasses MFA to Hijack Microsoft Accounts via OAuth Code

by Nam Phong · December 15, 2025

A new technique dubbed “ConsentFix” expands upon the already known ClickFix social engineering attack, enabling the hijacking of Microsoft accounts without passwords or multi-factor authentication. To achieve this, attackers exploit the legitimate Azure CLI application and nuances of OAuth authorization, effectively turning a standard sign-in flow into an account takeover mechanism.

ClickFix relies on presenting users with pseudo-system instructions that prompt them to run commands or complete seemingly benign steps, ostensibly to resolve an error or verify their “humanity.” The ConsentFix variant, documented by the Push Security team, preserves the overall deception but abandons malware installation in favor of stealing an OAuth 2.0 authorization code, which is then used to obtain an Azure CLI access token.

The attack begins when a victim lands on a compromised yet legitimate website that ranks well in Google search results for relevant queries. The page displays a fake Cloudflare Turnstile widget requesting a work email address. The attackers’ script validates the submitted address against a precompiled target list and filters out bots, analysts, and incidental visitors. Only selected victims are presented with the next stage, styled to resemble a typical ClickFix workflow with ostensibly harmless verification steps.

Victims are instructed to click a sign-in button, which opens a genuine Microsoft domain in a separate tab. However, instead of the standard login page, they are shown an Azure authorization screen that generates an OAuth code specifically for Azure CLI. If an active Microsoft session exists, the user merely selects their account; otherwise, a normal login via the legitimate form occurs.

After successful authentication, the browser is redirected to localhost, and the address bar displays a URL containing the Azure CLI authorization code tied to the account. The final act of deception involves instructing the victim to paste this URL back into the malicious page. At that moment, the attacker can exchange the code for an access token and control the account via Azure CLI—without ever knowing the password or triggering multi-factor authentication. If a session is already active, no explicit login is required at all. To reduce the risk of exposure, the scenario is executed only once per IP address.

Push Security advises defensive teams to monitor anomalous Azure CLI activity, including logins from unfamiliar IP addresses, and to scrutinize the use of legacy Graph permissions, which this technique leverages to evade standard detection controls.

Related coverage

  • TAG-195 Deploys ChonkyChicken Modular Malware Framework
  • OVERCAST PANDA Conducts Physical Attacks on Laptops
  • AI Cyber Threat Trends Surge in 2025
  • macOS ClickFix EtherHiding: DPRK Backdoor Hides C2 in Ethereum Smart Contracts
  • Student Hacks IIT Websites After Cyber Security Rejection

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Azure CLIClickFixcloud securityConsentFixMFA BypassMicrosoft Account TakeoverOAuth 2.0phishingSocial Engineering

Follow:

  • Next story Total Takeover: Droidlock Android Malware Locks Phones, Records Screen, and Bypasses Security
  • Previous story The End of d_genocide(): Linux Kernel Removes Controversial Function Name in 6.19 Refactor

  • Recent Posts
  • Popular Posts
  • Tags
  • ENDLESSDOORS hidden backdoor in Zbtlink router firmware discovered by VulnCheck using rctl remote control Linux component masquerading as kernel threads with root access

    Vulnerability

    ENDLESSDOORS: Hidden Remote Control Found in Zbtlink Router Firmware

    August 7, 2026

  • iCloud Private Relay IP leak via three WebKit vulnerabilities DNS prefetch WebAuthn WebTransport bypassing proxy on iOS iPadOS macOS Safari and third-party browsers

    Vulnerability

    iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses

    August 7, 2026

  • Malware bypassing DNS security by connecting directly to C2 IP addresses Phorpiex SectopRAT Mozi botnet ZT-IP firewall detection Unit 42

    Malware

    45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses

    August 7, 2026

  • Tactical police unit responding to coordinated swatting attacks with emergency vehicles

    Cyber Security

    FBI Warns of Coordinated Swatting Attacks Nationwide

    August 7, 2026

  • Tails 7.10.1 emergency patch for CVE-2026-64560 Linux kernel POSIX CPU timer race condition allowing Tor Browser privilege escalation and user deanonymization

    Linux

    Tails 7.10.1: Emergency Patch for CVE-2026-64560 That Could Deanonymize Users

    August 7, 2026

  • VMware vCenter vulnerability CVE-2026-59309 and CVE-2026-59310 rated CVSS 9.8 authentication bypass

    Vulnerability Report

    VMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8

    July 29, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source Penetration Testing phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro