You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cophish
About this tag
CoPhish is an attack chain identified by Datadog Security Labs that weaponizes Microsoft Copilot Studio to steal OAuth tokens. By hosting malicious agents on Microsoft domains, attackers use the agents' built-in sign-in workflows to deliver convincing OAuth consent prompts, exfiltrating tokens to attacker infrastructure. This technique highlights a security risk in low-code AI assistant platforms, where trusted Microsoft domains can be abused for phishing. Discussions on WindowsForum cover the technical details of the CoPhish attack, including how Copilot Studio's customizable topics and hosted demo pages enable token theft, and offer mitigation advice for enterprise IT and security professionals.
Microsoft’s Copilot Studio can be weaponized to steal OAuth tokens — an attack chain Datadog Security Labs has dubbed “CoPhish” — by hosting malicious agents on Microsoft domains and using the agents’ built‑in sign‑in workflows to deliver convincing OAuth consent prompts that exfiltrate tokens...