Threats

Microsoft 365 Account Hijacking

July 3, 2026 00:09 · 12 min read
Microsoft 365 Account Hijacking

Introduction to ConsentFix and ClickFix Attacks

ConsentFix and ClickFix are two types of attacks that can hijack Microsoft 365 accounts in a matter of seconds. These attacks work by exploiting routine user actions and workflows, making them difficult to detect and prevent.

The ConsentFix attack targets Microsoft 365's OAuth consent flows, which are the sign-in prompts that users have learned to breeze through without much scrutiny. The attack starts with a phishing lure, often delivered through trusted platforms like Dropbox or DocSend, which asks the victim to complete a standard Microsoft authentication screen by dragging a localhost callback link into the browser.

How ConsentFix Works

The victim unknowingly surrenders OAuth tokens, handing the attacker session access to email and other Microsoft 365 services without a password and MFA bypass. The victim isn't typing credentials into a fake form; they're completing what appears to be a legitimate authentication flow, and the session itself is what gets stolen.

Figure 1 shows the ClickFix-style fake verification prompt, which instructs the victim to press a sequence of keyboard shortcuts, pasting and executing attacker-supplied commands on their own machine.

ClickFix Attacks

ClickFix attacks work by showing a fake prompt instructing the victim to press a sequence of keyboard shortcuts, which pastes and executes attacker-supplied commands on their own machine. There’s no vulnerability to exploit and no firewall confrontation. Just a convincing lie inserted at the right moment.

ClickFix surged in 2025 and remains active, but attackers have already evolved the concept into something more sophisticated, such as ConsentFix.

Why These Attacks Keep Working

These attacks work because of habits we've all built up online, such as clicking through CAPTCHAs, accepting cookie prompts, and pressing a key combination to move a process along. That trained reflexiveness is exactly what attackers are counting on.

The attacker's job is to interrupt a normal workflow at exactly the right moment and let the victim do the rest. Understanding that pattern is the first step toward stopping it.

Reducing Exposure to ConsentFix and ClickFix Attacks

Awareness still has a role in preventing these attacks. Asking why a website wants you to press hotkeys or drag a strange link into a browser is often enough to short-circuit the whole thing.

However, awareness alone won't close the gap, because these attacks are specifically engineered to look routine. Defenders also need detection coverage for the traces they leave behind, such as unusual PowerShell activity originating from normal user processes, or new session logins from unexpected locations.

Endpoint and identity monitoring can surface those signals before a brief lapse in judgment snowballs into a full account compromise.

Criminal Underground and Attack Evolution

By early March 2026, a detailed walkthrough of ConsentFix had been posted to a public Russian cybercrime forum. It included working code, infrastructure screenshots, and a video tutorial showing exactly how to build and deploy the attack.

The infrastructure leaned on free or widely available services, and the post also outlined how attackers profile targets before sending a single phishing message, using LinkedIn and similar tools to map organizations and tailor lures to real people.

What was once a technique requiring meaningful technical skill now comes packaged with documentation and step-by-step guidance. The barrier to entry keeps dropping.

Conclusion

ConsentFix and ClickFix attacks are a serious threat to Microsoft 365 accounts, and understanding how they work is crucial to preventing them. By being aware of the tactics used by attackers and implementing detection and prevention measures, organizations can reduce their exposure to these types of attacks.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free