logo

Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat

ID: 0ef1e941-a256-5e56-9476-62e6bdf50a8b

STIX ID: report--0ef1e941-a256-5e56-9476-62e6bdf50a8b

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

...
...

Researchers observed a surge in attackers abusing Microsoft 365 mailbox rules—creating stealthy forwarding, suppression, or deletion rules immediately after compromise—to exfiltrate data, hide alerts, hijack conversations, and persist even after password resets; Proofpoint reports about 10% of breached accounts in Q4 2025 contained malicious rules, and recommended defenses include disabling auto-forwarding, enforcing MFA, monitoring OAuth, removing malicious rules, revoking sessions, and auditing account activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.