Outlook add-in goes rogue and steals 4,000 credentials and payment data
ID: 621c95a6-b2d4-59a0-ae42-9f345e21bb56
STIX ID: report--621c95a6-b2d4-59a0-ae42-9f345e21bb56
Feed Name: Malwarebytes Blog
Researchers found that an abandoned Microsoft Outlook add-in, AgreeTo, had its expired Vercel backend reclaimed by an attacker who deployed a four‑page phishing kit inside Outlook’s sidebar. The add-in abused previously-approved ReadWriteItem permissions to present a fake Microsoft sign-in, exfiltrate credentials and payment data to a Telegram bot, and then redirect victims to the real Microsoft login; investigators recovered over 4,000 stolen account credentials and associated financial data, and linked the operation to a multi-brand phishing campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
