logo

Outlook add-in goes rogue and steals 4,000 credentials and payment data

ID: 621c95a6-b2d4-59a0-ae42-9f345e21bb56

STIX ID: report--621c95a6-b2d4-59a0-ae42-9f345e21bb56

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-28

...
...

Researchers found that an abandoned Microsoft Outlook add-in, AgreeTo, had its expired Vercel backend reclaimed by an attacker who deployed a four‑page phishing kit inside Outlook’s sidebar. The add-in abused previously-approved ReadWriteItem permissions to present a fake Microsoft sign-in, exfiltrate credentials and payment data to a Telegram bot, and then redirect victims to the real Microsoft login; investigators recovered over 4,000 stolen account credentials and associated financial data, and linked the operation to a multi-brand phishing campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.