Glossary
Illicit consent grant
A phishing technique in which the victim is tricked into authorizing an attacker's OAuth app, which then accesses their data with a token.
An illicit consent grant (consent phishing) tricks a user into clicking "Allow" on an OAuth app controlled by the attacker, for example a fake "PDF viewer". The app receives a token for the requested OAuth scopes, such as full Gmail access, and can use it without the password. The token survives a password reset until it is revoked.
In Google Workspace the grant is the authorize event in the OAuth token log, and its use shows as activity events. MITRE: T1528.