Skip to content

Delivery technique · MITRE ATT&CK T1528

OAuth consent phishing

Tricking a user into granting a malicious or look-alike app access to their account, which keeps working after a password reset.

How it works

  1. The victim is sent to a real consent screen for an attacker-controlled app.
  2. Approving it issues tokens to the attacker.
  3. The tokens read mail, files, or CRM data without the password.

Defenses

Reference: MITRE ATT&CK T1528 Steal Application Access Token

Scams that use it

Cases