Microsoft 365 mailbox rules abused for exfiltration, persistence
ID: 97912ade-9869-5a3b-b64f-deee8542606c
STIX ID: report--97912ade-9869-5a3b-b64f-deee8542606c
Feed Name: Proofpoint Blog
Security vendors report attackers are creating malicious Microsoft 365 mailbox rules to automatically forward, delete, or suppress emails — including security alerts, MFA notifications, and password resets — enabling stealthy data exfiltration and persistence that survives password resets and MFA enrollment. Proofpoint observed this technique in roughly 10% of compromised accounts in Q4 2025; recommended mitigations include removing unauthorized inbox rules, invalidating sessions and refresh tokens, removing unrecognized apps, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
