Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts
ID: c3191b82-19fb-59e2-8f17-7ed743fa0c13
STIX ID: report--c3191b82-19fb-59e2-8f17-7ed743fa0c13
Feed Name: Bleeping Computer
A malicious actor hijacked the abandoned AgreeTo Outlook add-in on the Microsoft Marketplace and converted it into a phishing kit that served a fake Microsoft login in the Outlook sidebar, stealing over 4,000 Microsoft account credentials plus financial data. The add-in loaded resources from a Vercel-hosted URL claimed by the attacker, exfiltrated credentials via a Telegram bot, and redirected victims to the real Microsoft login to reduce suspicion; the module also retained ReadWriteItem permissions. Koi Security discovered the compromise and Microsoft removed the add-in after the findings were reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
