
New CoPhish Attack Exploits Copilot Studio to Exfiltrate OAuth Tokens
The digital frontier is constantly under siege, and sophisticated attackers are always perfecting their craft. A new, particularly insidious phishing technique, dubbed CoPhish, has emerged, exploiting the trusted environment of Microsoft Copilot Studio to compromise Microsoft Entra ID accounts. This novel attack, uncovered by Datadog Security Labs, represents a significant escalation in the battle against identity theft, wrapping traditional OAuth consent attacks in a veneer of legitimacy that bypasses conventional user suspicion.
Understanding the CoPhish Attack Vector
The CoPhish attack is ingenious in its simplicity and effectiveness. It leverages Microsoft Copilot Studio (formerly Microsoft Power Virtual Agents) to create custom AI agents. These agents, hosted on legitimate Microsoft domains, are then weaponized to facilitate OAuth token exfiltration. The key to its success lies in the domain’s trustworthiness; users are conditioned to trust Microsoft domains, significantly lowering their guard against phishing attempts.
Attackers configure these AI agents to initiate an OAuth flow, requesting permissions that appear innocuous but, if granted, provide broad access to a user’s Microsoft Entra ID account. This isn’t a direct exploitation of a vulnerability within Copilot Studio itself, but rather a misuse of its legitimate functionality to create a highly convincing phishing lure. The customizable nature of these AI agents allows attackers to craft highly targeted and personalized messages, further increasing the success rate of their campaigns.
How CoPhish Exploits OAuth Consent
OAuth (Open Authorization) is an open standard for access delegation, commonly used by internet users to grant websites or applications access to their information on other websites without giving them their passwords. While incredibly useful, OAuth consent flows can be exploited. In a CoPhish attack, the malicious Copilot Studio agent directs the user to an OAuth consent screen. This screen appears legitimate because it originates from a Microsoft domain.
- Legitimate Domain Hosting: The core deception hinges on the fact that the malicious AI agent and the subsequent OAuth prompt are hosted directly on Microsoft’s infrastructure. This bypasses many organizational email filters and user-level suspicion concerning untrusted URLs.
- Social Engineering: Attackers craft compelling narratives to convince users to interact with the deceptive AI agent. This often involves urgent requests, promises of new features, or security alerts designed to induce a quick, unthinking response.
- Token Exfiltration: Once the user grants consent, the attacker gains an OAuth token. This token can then be used to access various resources within the user’s Microsoft Entra ID account, potentially leading to data exfiltration, privilege escalation, or further lateral movement within an organization’s network.
Remediation Actions and Mitigations
Defending against sophisticated phishing attacks like CoPhish requires a multi-layered approach, combining robust technical controls with continuous user education.
- Enhanced User Education: Conduct regular, realistic phishing simulations that include scenarios mimicking CoPhish attacks. Train users to scrutinize all requests for permissions, even those appearing to come from legitimate sources, and to report suspicious activity. Emphasize verification procedures for any application requesting access to their accounts.
- Implement Conditional Access Policies: Leverage Microsoft Entra ID Conditional Access to enforce strict rules around application consent.
- Review and Audit OAuth Consents: Regularly audit user and application OAuth consents within Microsoft Entra ID. Revoke permissions for any applications that are not recognized or are no longer needed. Pay close attention to permissions granted to applications with broad access scopes.
- Monitor for Unusual Activity: Implement robust logging and monitoring for anomalous activities related to OAuth token usage, application consent, and unusual mail client behavior. Look for large data downloads, access from unusual locations, or changes in user settings.
- Least Privilege Principle: Adhere to the principle of least privilege for all applications and users. Only grant the necessary permissions required for an application or user to perform its intended function.
- Multi-Factor Authentication (MFA): Enforce strong MFA across all Microsoft Entra ID accounts. While MFA doesn’t prevent token exfiltration, it can limit the immediate impact by preventing direct password-based attacks if the token expires or is somehow invalidated.
Tools for Detection and Mitigation
Organizations can leverage various tools and native Microsoft 365 security features to detect and mitigate the risks posed by CoPhish and similar attacks.
| Tool Name | Purpose | Link |
|---|---|---|
| Microsoft Entra ID Protection | Detects identity-based risks, including suspicious sign-ins and unusual user behavior. | Microsoft Entra ID Protection |
| Microsoft Defender for Cloud Apps (MDCA) | Provides visibility into cloud apps, identifies and combats cyberthreats, and controls data transfer across apps. Useful for monitoring OAuth app activity. | Microsoft Defender for Cloud Apps |
| Microsoft Purview Audit (Premium) | Offers detailed auditing capabilities for user and admin activities, including application consent events. | Microsoft Purview Audit Solutions |
| Phishing Simulation Platforms | Tools like KnowBe4, Proofpoint, or Cofense to conduct controlled phishing exercises and train employees. | KnowBe4 (Example) |
Conclusion
The CoPhish attack underscores the evolving sophistication of cyber threats and the critical importance of a proactive security posture. By weaponizing Microsoft Copilot Studio, attackers are bypassing traditional security assurances and leveraging trust in legitimate domains to compromise user accounts and exfiltrate sensitive OAuth tokens. Defending against such advanced techniques necessitates a robust defense-in-depth strategy, combining vigilant user education, stringent access policies, continuous monitoring, and the strategic deployment of security tools. Organizations must remain agile, adapting their defenses as new threat vectors emerge, to protect their digital assets and user identities from these increasingly clever adversaries.


