Menu
BREAKING NEWS

CoPhish Attack Exploits Microsoft Copilot Studio to Steal OAuth Tokens

Uday Patil Oct 27, 2025 6 min read 77 views
CoPhish Attack Exploits Microsoft Copilot Studio to Steal OAuth Tokens

As enterprise organizations accelerate the adoption of low-code artificial intelligence tooling, cybercrime syndicates are finding novel vectors to weaponize trusted corporate cloud ecosystems. Cybersecurity researchers have uncovered an advanced attack methodology dubbed the CoPhish attack, which exploits Microsoft Copilot Studio to deceive enterprise users into granting malicious applications unconstrained administrative access to their Microsoft Entra ID tenants.

CoPhish attack flow diagram exploiting Microsoft Copilot Studio and Entra ID

According to technical vulnerability disclosures published by Datadog Security Labs, the intrusion vector represents an acute evolution of traditional OAuth consent abuses. Rather than relying on suspicious external phishing domains, threat actors host deceptive, customizable chatbots directly within Microsoft’s official cloud boundaries, exploiting the implicit trust employees place in verified enterprise software.

Threat Architecture: How the CoPhish Attack Weaponizes Microsoft Copilot Studio

Traditional corporate defense perimeters heavily rely on reputation-based domain filtering to block malicious links. When a link resolves to an official Microsoft domain—specifically copilotstudio.microsoft.com—enterprise email gateways and browser filters inherently classify the destination as safe. The CoPhish attack systematically exploits this architectural blind spot.

Adversaries utilize trial licenses or compromised enterprise credentials to build custom AI agents inside Copilot Studio. The attackers manipulate the platform’s native “Login” topic workflow, embedding a backdoored HTTP request designed to exfiltrate OAuth session tokens to an external command-and-control server immediately after user consent.

Microsoft Copilot Studio interface demonstrating the CoPhish attack workflow
Attack StageAdversarial MechanismInfrastructure LayerEnterprise Security Impact
Lure DeliveryShared Copilot Studio demo web linkscopilotstudio.microsoft.comBypasses URL reputation scanners and user skepticism
Credential PromptingCustom AI chatbot prompting for corporate loginCopilot Studio “Login” topic workflowSimulates standard Microsoft authentication challenges
OAuth GrantUser consents to application scopesMicrosoft Graph API permissionsGrants read/write access to corporate email, OneNote, and calendars
Silent ExfiltrationAutomated HTTP webhook token transmissiontoken.botframework.com & Microsoft IPsObfuscates exfiltration traffic from endpoint network logs

Deep Dive: Exploiting OAuth Consent and Microsoft Graph Permissions

The CoPhish technique aligns directly with MITRE ATT&CK technique T1528 (Steal Application Access Token). In Microsoft Entra ID (formerly Azure Active Directory) environments, enterprise applications require specific permission scopes to interact with corporate resources via Microsoft Graph.

When an employee interacts with the weaponized Copilot Studio chatbot, they are presented with an authentic Microsoft Entra authentication dialogue. The requested permissions vary depending on the organizational privileges of the targeted victim:

  • Internal Workforce Targets: For unprivileged corporate staff, the rogue application requests allowable user scopes such as Notes.ReadWrite, Calendars.ReadWrite, or Mail.ReadWrite. Because standard tenant policies frequently allow basic user consent, these permissions are granted without administrative review.
  • Administrative Privileges: If an Application Administrator or Global Administrator interacts with the agent, the malicious application escalates its requests, demanding tenant-wide administrative scopes like Directory.ReadWrite.All or Files.ReadWrite.All, effectively compromising the entire organizational tenant.

Post-consent, a verification code is generated via token.botframework.com to complete the workflow. However, the backdoored Copilot topic routes the resulting access token directly to an external server. Because the HTTP exfiltration originates from Microsoft’s internal IP infrastructure, network monitoring tools observe normal cloud traffic rather than an active data breach.

For an overarching architectural blueprint on mitigating autonomous AI agents and OAuth abuse across enterprise infrastructure, explore our definitive AI Cyber Threats and Agentic Security Guide.

Actionable Hardening: 5 Critical Defense Steps for Enterprise Administrators

Relying solely on default Microsoft tenant configurations leaves corporate identity perimeters vulnerable to hybrid AI phishing. Enterprise security leadership must implement strict operational guardrails across Microsoft Entra ID and Copilot Studio:

Step 1: Enforce Strict Administrative Consent Policies

Disable end-user consent for all enterprise applications interacting with organizational data:

  • Navigate to identity configuration: Access Microsoft Entra Admin Center > Identity > Applications > Enterprise applications > Consent and permissions.
  • Enforce policy: Select “Do not allow user consent.” Mandate that all third-party application requests require formal administrative review and approval.
  • Implement admin consent workflow: Configure an automated ticketing workflow allowing legitimate business requests to be evaluated by identity security engineers before permissions are bound.

Step 2: Restrict Copilot Studio Agent Creation and Public Sharing

Prevent unauthorized internal users or rogue accounts from staging unmonitored chatbot workflows:

  • Govern trial licenses: Disable unmonitored self-service signups for Power Platform and Copilot Studio trial licenses via tenant PowerShell administration.
  • Disable public demo channels: Restrict the ability to publish Copilot Studio agents to public demo websites (copilotstudio.microsoft.com/demo) without explicit organizational approval.

Step 3: Deploy Conditional Access with Continuous Access Evaluation (CAE)

Mitigate the operational lifespan of stolen OAuth tokens by enforcing real-time identity telemetry:

  • Require compliant devices: Mandate that access to Microsoft 365 and Microsoft Graph APIs is granted exclusively to Intune-compliant, enterprise-managed devices.
  • Enforce Continuous Access Evaluation: Enable CAE across Entra ID to ensure tokens are revoked immediately upon password changes, location anomalies, or user risk elevations.

Step 4: Audit Entra ID Audit Logs and OAuth Grants

Continuously monitor tenant telemetry for unauthorized application registrations and suspicious consent events:

  • Track OAuth grants: Query Entra ID audit logs for event names such as Consent to application and Add service principal.
  • Inspect permission anomalies: Flag any application requesting access to mailboxes, calendars, or directory structures from non-standard geographic locations.

Step 5: Mandate Phishing-Resistant FIDO2 Authentication

Deploy hardware security keys (such as YubiKeys or Windows Hello passkeys) across all administrative accounts. FIDO2 credentials enforce cryptographic origin binding, ensuring that captured authentication tokens cannot be trivially weaponized through automated reverse proxies.

Frequently Asked Questions (FAQ)

What is the CoPhish attack in Microsoft Copilot Studio?

The CoPhish attack is a sophisticated phishing technique discovered by Datadog Security Labs where threat actors exploit Microsoft Copilot Studio to build malicious AI chatbots hosted on legitimate Microsoft domains. These chatbots prompt users to log in, stealing OAuth access tokens to compromise Microsoft Entra ID accounts.

Why is the CoPhish attack difficult for security filters to detect?

The attack operates entirely within Microsoft’s legitimate domain infrastructure (copilotstudio.microsoft.com). Because the URL reputation is completely benign, traditional secure email gateways and web proxies do not flag the links as malicious, and token exfiltration traffic is routed through Microsoft IP addresses.

What data can attackers access with stolen OAuth tokens?

Depending on the consented scopes, attackers can read and send corporate emails, access OneNote documents, manipulate calendar schedules, and exfiltrate internal files. If an administrator is compromised, the attacker can achieve persistent, tenant-wide administrative control.

Conclusion: Securing Identity in the Era of Enterprise AI

The emergence of the CoPhish attack underscores an urgent reality in enterprise cybersecurity: as artificial intelligence tools integrate into core productivity suites, threat actors will weaponize legitimate cloud environments to bypass traditional perimeter security.

Securing enterprise identity in this environment requires strict OAuth consent governance, continuous API audit logging, and the elimination of unverified third-party application trust. By enforcing robust administrative oversight and zero-trust controls, organizations can leverage enterprise AI safely without exposing corporate assets to automated identity exploitation.

Reported by CyberUpdates365 Threat Intelligence Desk. Delivering actionable research on cloud identity defense, AI security architectures, and enterprise threat mitigation.

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.