Experts warn Microsoft Copilot Studio agents are being hijacked to steal OAuth tokens

Experts warn Microsoft Copilot Studio agents are being hijacked to steal OAuth tokens



  • CoPhish uses Copilot Studio agents to phish OAuth tokens via fake login flows
  • Attackers exploit Microsoft domains to appear legitimate and access sensitive user data
  • Mitigations include restricting app consent, enforcing MFA, and monitoring OAuth activity

Security researchers from Datadog Security Labs are warning about a new phishing technique weaponizing Microsoft Copilot Studio agents to steal OAuth tokens and grants attackers access to sensitive information in emails, chats, calendars, and more.

The technique is named CoPhish, and while Microsoft confirmed it is a social engineering technique, it acknowledged it and said it will work on addressing it.





Source: Techradar

Leave a Reply

Your email address will not be published. Required fields are marked *