logo

AgreeToSteal: A Dead Outlook Add-In Became Microsoft's First Marketplace Phishing Weapon

ID: f6be097a-510c-5e32-bb6a-2f79506b9216

STIX ID: report--f6be097a-510c-5e32-bb6a-2f79506b9216

Feed Name: NoHackie

Threat Score
78/100

Date Published: 2026-02-13

Date Updated: 2026-04-19

...
...

Koi Security disclosed AgreeToSteal (Feb 2026), the first known malicious Outlook add-in in the wild: an attacker claimed an abandoned Vercel subdomain referenced by a Microsoft-approved add-in manifest and served a four-page phishing kit inside Outlook's sidebar, exfiltrating >4,000 Microsoft account credentials, credit card numbers, and banking answers via a Telegram bot. The report explains the core architectural flaw (Office add-ins load mutable remote URLs approved once at submission), outlines why email gateways, EDR, URL filtering, and identity protections miss this vector, and recommends mitigations such as content re-validation, domain ownership checks, abandonment detection, allowlisting, and phishing-resistant authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.