Attackers Weaponize Mailbox Rules to Control Your Inbox
ID: ae02a5c8-8fda-557b-9b50-f47a744decce
STIX ID: report--ae02a5c8-8fda-557b-9b50-f47a744decce
Feed Name: securityonline.info
Proofpoint research shows attackers increasingly use malicious Microsoft 365 mailbox rules as a stealthy post-compromise persistence and exfiltration method: roughly 10% of compromised accounts in Q4 2025 had such rules, which can be created within seconds of takeover. These rules forward, delete, or hide messages (including MFA alerts and security notifications), remain active after password changes, and can be deployed at scale via automated tools like ATOLS that capture session tokens and programmatically create rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
