Malicious Connectors Potentially Impact Hundreds of Millions of Microsoft 365 Users
ID: f526f21c-9001-5a79-84a4-d289e7ba8bc2
STIX ID: report--f526f21c-9001-5a79-84a4-d289e7ba8bc2
Feed Name: KnowBe4 Blog
The report warns that attackers are increasingly abusing Microsoft 365 Outlook rules, forms, and Exchange connectors to maintain persistence, conceal activity, and facilitate payment fraud after account compromise—often via adversary-in-the-middle phishing that steals session cookies despite MFA. It highlights that these server-side connectors are easy to miss, persist across password changes, and are now common enough that Microsoft provides specific guidance; it includes steps to locate and review connectors, recommends enabling phishing-resistant MFA (e.g., FIDO), monitoring for creation/modification of rules/forms/connectors, and watching for anomalies like mismatched 5321.MailFrom and 5322.From in headers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
