Executive Summary
In early June 2024, security researchers discovered a sophisticated phishing campaign dubbed 'CoPhish' exploiting Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests. By leveraging legitimate Microsoft domains and trusted Copilot workflows, attackers deceived enterprise users into granting malicious apps access to their Microsoft 365 accounts, thereby stealing OAuth tokens and enabling unauthorized access to sensitive emails, files, and collaborative workspaces. The attack chain bypassed traditional email security controls due to its reliance on trusted infrastructure and social engineering, putting multiple organizations at risk of data compromise and account takeover.
This incident underscores the growing trend of threat actors abusing trusted cloud and AI-powered collaboration platforms, capitalizing on user trust and shadow IT. It highlights urgent security concerns around identity-driven attacks, modern authentication abuse, and the need for enhanced vigilance in managing third-party OAuth authorizations.
Why This Matters Now
The CoPhish campaign demonstrates a rapid evolution in phishing tactics, where attackers use trusted enterprise AI tools and native app platforms to exploit identity and access controls. Organizations must urgently reassess their OAuth consent governance and cloud access security protocols as increasingly sophisticated, native-cloud threats emerge targeting business-critical data.
Attack Path Analysis
The attack begins with users being tricked into granting OAuth consent to malicious Copilot Studio agents through phishing emails or trusted Microsoft domains. Once consent is given, attackers harvest access tokens and may escalate privileges by abusing OAuth scopes or connected permissions. The attackers use the stolen tokens to laterally access additional cloud resources or SaaS applications tied to the victim's account. Command and control is maintained via application programming interfaces and outbound communication from the compromised platform. The adversary exfiltrates sensitive data or tokens to external infrastructure, and the overall impact may include data loss, account takeover, or persistent cloud access.
Kill Chain Progression
Initial Compromise
Description
Victims are targeted with phishing links leading to fraudulent OAuth consent requests via trusted Microsoft Copilot Studio agents.
Related CVEs
CVE-2024-38206
CVSS 9.1A server-side request forgery (SSRF) vulnerability in Microsoft Copilot Studio allows unauthenticated attackers to access internal infrastructure, potentially exposing sensitive data.
Affected Products:
Microsoft Copilot Studio – All versions prior to the patch released on August 20, 2024
Exploit Status:
exploited in the wildReferences:
https://www.aha.org/h-isac-white-reports/2024-08-22-h-isac-tlp-white-vulnerability-bulletin-critical-microsoft-copilot-studio-vulnerability-exposeshttps://www.aha.org/system/files/media/file/2024/08/h-isac-tlp-whtie-vulnerability-bulletin-critical-microsoft-copilot-studio-vulnerability-cve-2024-38206-exposes-sensitive-data18-21-2024.pdfCVE-2024-43610
CVSS 7.5An information disclosure vulnerability in Microsoft Copilot Studio allows unauthenticated attackers to view sensitive information through network attack vectors.
Affected Products:
Microsoft Copilot Studio – All versions prior to the patch released on October 9, 2024
Exploit Status:
no public exploitCVE-2024-49038
CVSS 6.1A cross-site scripting (XSS) vulnerability in Microsoft Copilot Studio allows unauthorized attackers to elevate privileges over a network.
Affected Products:
Microsoft Copilot Studio – All versions prior to the patch released on November 26, 2024
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Phishing
Steal Application Access Token
Use Alternate Authentication Material: Web Session Cookie
Valid Accounts: Cloud Accounts
Account Discovery: Cloud Account
Brute Force: Password Spraying
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor authentication for all access into CDE
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management
Control ID: Article 10(1)
CISA ZTMM 2.0 – Continuous Authentication Validation
Control ID: Identity Pillar – Authentication: 3.1
NIS2 Directive – Access Control Policies
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
CoPhish phishing attacks targeting OAuth tokens through Microsoft Copilot Studio pose critical risks to financial institutions requiring strict regulatory compliance and customer data protection.
Health Care / Life Sciences
Healthcare organizations face severe HIPAA compliance violations and patient data breaches from CoPhish attacks exploiting trusted Microsoft domains for fraudulent OAuth consent requests.
Information Technology/IT
IT sectors are primary targets for CoPhish attacks leveraging Microsoft Copilot Studio agents, requiring enhanced multicloud visibility, zero trust segmentation, and threat detection capabilities.
Government Administration
Government agencies face heightened security risks from CoPhish phishing campaigns exploiting legitimate Microsoft domains, demanding robust egress security and anomaly detection for sensitive operations.
Sources
- New CoPhish attack steals OAuth tokens via Copilot Studio agentshttps://www.bleepingcomputer.com/news/security/new-cophish-attack-steals-oauth-tokens-via-copilot-studio-agents/Verified
- Critical Microsoft Copilot Studio Vulnerability (CVE-2024-38206) Exposes Sensitive Datahttps://www.aha.org/h-isac-white-reports/2024-08-22-h-isac-tlp-white-vulnerability-bulletin-critical-microsoft-copilot-studio-vulnerability-exposesVerified
- NVD - CVE-2024-43610https://nvd.nist.gov/vuln/detail/CVE-2024-43610Verified
- NVD - CVE-2024-49038https://nvd.nist.gov/vuln/detail/CVE-2024-49038Verified
- CoPhish Attack Exploits Microsoft Copilot Studio to Steal OAuth Tokens via Malicious Agentshttps://www.rescana.com/post/cophish-attack-exploits-microsoft-copilot-studio-to-steal-oauth-tokens-via-malicious-agentsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive CNSF controls—including egress policy enforcement, zero trust segmentation, anomaly detection, and granular visibility—could have detected fraudulent consent activity, constrained token misuse, and limited attackers’ ability to pivot or exfiltrate sensitive cloud data.
Control: Threat Detection & Anomaly Response
Mitigation: Detection of anomalous OAuth consent behavior would alert on suspicious application authorization.
Control: Zero Trust Segmentation
Mitigation: Identity-based segmentation and least privilege policies would contain access and prevent escalation.
Control: East-West Traffic Security
Mitigation: Inspection and policy enforcement on internal cloud communications would detect and block lateral traversal.
Control: Cloud Firewall (ACF)
Mitigation: Outbound API communications to unapproved destinations would be restricted, disrupting C2 channels.
Control: Egress Security & Policy Enforcement
Mitigation: Policy-driven egress controls detect and block unauthorized data exfiltration attempts.
Centralized visibility and alerting enable rapid response to prevent wider business or reputational damage.
Impact at a Glance
Affected Business Functions
- Email Communications
- Calendar Management
- Document Management
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive emails, calendar events, and documents due to unauthorized access via stolen OAuth tokens.
Recommended Actions
Key Takeaways & Next Steps
- • Implement anomaly detection and continuous monitoring for OAuth consent flows and cloud application authorizations.
- • Enforce zero trust segmentation with identity-based policies to compartmentalize and restrict movement of compromised tokens.
- • Apply strict egress controls and cloud firewalling to block outbound data transfers to unauthorized endpoints.
- • Increase east-west visibility and internal traffic inspection to detect and prevent lateral movement in cloud environments.
- • Enable centralized, multi-cloud observability to accelerate incident detection and remediation across all workloads.



