logo

Outlook add-in goes rogue and steals 4,000 credentials and payment data

ID: 48beaea3-e89f-5b91-8537-a3ed4aa48179

STIX ID: report--48beaea3-e89f-5b91-8537-a3ed4aa48179

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Malwarebytes

...
...

Malwarebytes reports that an abandoned Outlook add-in called AgreeTo was hijacked after its Vercel backend URL expired; an attacker claimed the subdomain and replaced the add-in content with a four-page phishing kit that harvested Microsoft credentials and payment/banking data, exfiltrating entries via a Telegram bot. Researchers recovered over 4,000 stolen Microsoft account credentials and evidence the operator runs at least a dozen multi-brand phishing kits, making this an active and organized credential-theft campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.