Cybersecurity researchers have uncovered a new phishing campaign called CoPhish, which abuses Microsoft Copilot Studio agents to steal OAuth tokens. The attack leverages legitimate Microsoft infrastructure, making it difficult to detect or block through traditional security filters.

The CoPhish attack OAuth tokens campaign primarily targets Microsoft 365 users. By creating convincing Copilot agents within Microsoft’s trusted domains, attackers trick users into granting malicious OAuth permissions that give them unauthorized access to emails, chats, and files.

How the CoPhish attack works

The attackers design fake Copilot Studio agents that appear legitimate. These agents use a “Login” topic to lure victims into an OAuth consent workflow. When users interact with the agent, they are redirected to a Microsoft login page that looks authentic.

Once the victim approves the consent request, the attacker receives an OAuth token that grants persistent access to Microsoft 365 resources. This token allows them to read and send emails, access Teams chats, download files, and even move laterally across the organization — all without triggering standard login alerts.

Because the entire process occurs under genuine Microsoft domains like copilotstudio.microsoft.com, many security tools fail to flag the activity as suspicious.

Targets and potential impact

The CoPhish attack affects both individual users and corporate administrators. Regular employees can unknowingly grant permission to internal data, while admins may expose organization-wide resources. The stolen tokens can be used to exfiltrate emails, modify calendar data, or deploy follow-up phishing messages.

Researchers warn that these attacks highlight the growing threat of phishing inside trusted ecosystems. The blend of legitimate Microsoft tools and deceptive social engineering makes detection extremely challenging.

Preventing OAuth token theft

To mitigate this threat, organizations should restrict who can create custom Copilot Studio agents. Microsoft recommends disabling user app registrations by default and enforcing admin approval for all new OAuth consent requests. Security teams should also monitor for unusual agent creation or consent activities in audit logs.

User education remains equally important. Employees must learn to verify every consent prompt and report unexpected login requests, even when they appear to come from official Microsoft sources.

Conclusion

The CoPhish attack OAuth tokens campaign shows how cybercriminals increasingly exploit AI and automation platforms to bypass defenses. By abusing Microsoft Copilot Studio agents, attackers transform legitimate tools into phishing delivery systems. Strengthening OAuth governance and training users to spot malicious consent requests are essential steps in preventing similar identity-based attacks in the future.


0 responses to “CoPhish attack steals OAuth tokens through Microsoft Copilot Studio agents”