logo

Attackers Weaponize Mailbox Rules to Control Your Inbox

ID: ae02a5c8-8fda-557b-9b50-f47a744decce

STIX ID: report--ae02a5c8-8fda-557b-9b50-f47a744decce

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Proofpoint research shows attackers increasingly use malicious Microsoft 365 mailbox rules as a stealthy post-compromise persistence and exfiltration method: roughly 10% of compromised accounts in Q4 2025 had such rules, which can be created within seconds of takeover. These rules forward, delete, or hide messages (including MFA alerts and security notifications), remain active after password changes, and can be deployed at scale via automated tools like ATOLS that capture session tokens and programmatically create rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.