“ConsentFix” Phishing Attacks & Why They Matter: Stealthily Stealing OAuth Access via the Browser
ConsentFix is a newly observed browser-based phishing technique. Named based on its purported predecessor, ClickFix, ConsentFix has similar social engineering prompts to ClickFix attacks. However, where ClickFix requires a user to paste malicious commands to compromise the host device, ConsentFix tricks a user into pasting an OAuth authorization code to an attacker-controlled site, thereby compromising the victim’s cloud account.