{"id":56155,"date":"2026-07-21T11:28:43","date_gmt":"2026-07-21T15:28:43","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=56155"},"modified":"2026-07-21T11:28:43","modified_gmt":"2026-07-21T15:28:43","slug":"consentfix-microsoft-365-account-hijacking","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/consentfix-microsoft-365-account-hijacking\/56155\/","title":{"rendered":"ConsentFix: yet another variation of the ClickFix attack"},"content":{"rendered":"<p>Cybercriminals are increasingly moving away from complex malware, relying instead on social engineering that exploits a common user habit: mindlessly clicking through endless digital rituals like CAPTCHAs, cookie consents, and authentication prompts. This habit is often targeted by various kinds of the <a href=\"https:\/\/www.kaspersky.com\/blog\/clickfix-attack-variations\/55340\/\" target=\"_blank\" rel=\"noopener nofollow\">ClickFix<\/a> technique, which threat actors have been actively using lately. Researchers recently discovered a new variant of this technique, which they dubbed <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds\/\" target=\"_blank\" rel=\"noopener nofollow\">ConsentFix<\/a>. It allows attackers to gain unauthorized access to Microsoft 365 accounts via OAuth\u00a0\u2014 a <a href=\"https:\/\/www.kaspersky.com\/blog\/google-oauth-email-hijacking-shadow-token-remote-debug\/56144\/\" target=\"_blank\" rel=\"noopener nofollow\">highly popular vector right now<\/a>\u00a0\u2014 thereby completely bypassing the need to steal passwords. For organizations, these attacks present a severe risk of compromised corporate email, exposed documents, and breached cloud resources.<\/p>\n<h2>How ConsentFix works<\/h2>\n<p>Social engineering lies at the core of all ClickFix variations. Attackers prompt the user to follow a seemingly harmless set of instructions, which actually lead to the compromise of their device or account. In the case of ConsentFix, these instructions are designed to trick the user into granting the attacker access to their Microsoft 365 account.<\/p>\n<p>The attack begins by making the user believe they must authenticate with their Microsoft account to access a specific page or document. To do this, cybercriminals usually send an email containing a link to a website typically imitating a popular file-sharing service. Attempting to access a specific document on this site prompts the user for verification, which can be obtained by following this sequence of actions:<\/p>\n<ol>\n<li>Clicking <em>Verify with Microsoft<\/em>.<\/li>\n<li>Signing in to the work account, at which point the attackers warn that multi-factor authentication (MFA) may be required.<\/li>\n<li>After being redirected to a new page, waiting until \u201clocalauth\u201d appears in the address bar.<\/li>\n<li>Dragging the information icon \u24d8 from the browser\u2019s address bar into a drop zone on the page.<\/li>\n<\/ol>\n<p>In practice, following these instructions causes the user to drag an URL containing a session OAuth token directly onto the attacker\u2019s page. This token is exactly what grants the attackers access to the victim\u2019s email and other Microsoft 365 services.<\/p>\n<h2>The potential fallout of a Microsoft 365 session compromise<\/h2>\n<p>At first glance, it might seem like attackers only gain access to a mailbox. In reality, the consequences can be significantly more severe. The attacker\u2019s specific capabilities depend on the organization\u2019s Microsoft 365 license, the services deployed, and the privilege level of the compromised account.<\/p>\n<p>Even <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/business\/microsoft-365-plans-and-pricing\" target=\"_blank\" rel=\"noopener nofollow\">basic corporate Microsoft 365 subscriptions<\/a> typically grant access to Outlook, Teams, OneDrive, and SharePoint, <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/enterprise\/microsoft-365-plans-and-pricing\" target=\"_blank\" rel=\"noopener nofollow\">while more advanced tiers<\/a> may include additional services and administrative tools.<\/p>\n<p>Even compromised corporate email alone is a major breach. The attacker not only gains access to email archives that may contain confidential business intelligence, but also can send phishing messages or launch <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-bec-attack\/34135\/\" target=\"_blank\" rel=\"noopener nofollow\">internal BEC attacks<\/a> on behalf of the user.<\/p>\n<p>Beyond email, attackers are highly likely to gain access to the victim\u2019s Microsoft Teams account, providing them with even deeper insights and broader leverage for various scams. Access to OneDrive and SharePoint is equally dangerous: it allows attackers to exfiltrate corporate documents, upload malware into cloud storage, tamper with existing files, and more. Ultimately, this creates a launchpad for moving laterally within the corporate infrastructure.<\/p>\n<h2>Publicly available attack blueprints<\/h2>\n<p>According to a <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds\/\" target=\"_blank\" rel=\"noopener nofollow\">Bleeping Computer article<\/a>, the mechanics of ConsentFix are no secret. Attackers share detailed implementation guides on cybercrime forums, offering not only ready-to-use code but also video tutorials demonstrating how to deploy the attack. They also actively trade tips on how they harvest intelligence on organizations and their employees via LinkedIn and other OSINT channels to craft highly convincing phishing messages.<\/p>\n<p>Collectively, this significantly lowers the barrier to entry for novice cybercriminals. As these guides and turnkey tools continue to proliferate, ConsentFix attacks will likely become increasingly common. Consequently, organizations should immediately factor this technique into both their defense strategies and employee awareness training programs.<\/p>\n<h2>How to secure your corporate infrastructure<\/h2>\n<p>The emergence of this new ClickFix variation demonstrates that simply blocking a specific keyboard shortcut or an isolated risky action on employee devices is not enough. Clearly, attackers quickly adapt to these measures. Therefore, to protect an organization from these types of attacks, we recommend the following:<\/p>\n<ul>\n<li>Be sure to deploy a <a href=\"https:\/\/www.kaspersky.com\/small-to-medium-business-security\/mail-security-appliance?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____\" target=\"_blank\" rel=\"noopener nofollow\">robust security solution<\/a> at the mail gateway level\u00a0\u2014 this minimizes the likelihood of attackers successfully luring your employees to a page hosting the ConsentFix mechanism.<\/li>\n<li>Conduct regular cybersecurity awareness training for employees to keep them ahead of the latest social engineering tactics. Our training platform, <a href=\"https:\/\/k-asap.com\/en\/?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____kasap___\" target=\"_blank\" rel=\"noopener\">Kaspersky Automated Security Awareness Platform<\/a>, can assist with this initiative.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kasap\">\n","protected":false},"excerpt":{"rendered":"<p>A new variation of ClickFix allows attackers to gain access to Microsoft 365 accounts. We break down how this technique works, and what threat it poses to organizations.<\/p>\n","protected":false},"author":2726,"featured_media":56156,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,3051,3052],"tags":[2141,4650,38,4600,2816,513,422],"class_list":{"0":"post-56155","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-enterprise","9":"category-smb","10":"tag-business","11":"tag-clickfix","12":"tag-microsoft","13":"tag-microsoft-365","14":"tag-office-365","15":"tag-social-engineering","16":"tag-threats"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/consentfix-microsoft-365-account-hijacking\/56155\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/consentfix-microsoft-365-account-hijacking\/30918\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/consentfix-microsoft-365-account-hijacking\/25950\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/consentfix-microsoft-365-account-hijacking\/30753\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/consentfix-microsoft-365-account-hijacking\/42320\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/consentfix-microsoft-365-account-hijacking\/30873\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/consentfix-microsoft-365-account-hijacking\/36418\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/consentfix-microsoft-365-account-hijacking\/36313\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/social-engineering\/","name":"social engineering"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56155","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=56155"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56155\/revisions"}],"predecessor-version":[{"id":56158,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56155\/revisions\/56158"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/56156"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=56155"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=56155"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=56155"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}