logo

Legitimate Apps as Traitorware for Persistent Microsoft 365 Compromise

ID: ccc4c11b-d6f9-511a-9282-a5647a5bd8bb

STIX ID: report--ccc4c11b-d6f9-511a-9282-a5647a5bd8bb

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress details a business email compromise in Microsoft 365 where an attacker used a compromised user account to add legitimate OAuth apps (eM Client, SuperMailer), grant delegated permissions including offline_access and Mail.Send/Mail.Read, and create inbox rules to hide incoming messages—allowing persistent, stealthy access via refresh tokens; the report highlights detection signals in Azure AD logs and recommends tightening consent controls and monitoring app/service-principal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.