HomeSecurityMalicious Outlook add-in stole over 4,000 Microsoft credentials

Malicious Outlook add-in stole over 4,000 Microsoft credentials

Cybersecurity researchers have discovered what they describe as the first known malicious Microsoft Outlook add-in to be detected in real attacks.

Outlook add-in

In this unusual supply chain attack, analyzed by Koi Security, an unknown attacker hijacked the domain associated with a now-defunct legitimate add-on to create a fake Microsoft login page and ultimately steal over 4,000 credentials. The activity has been codenamed AgreeToSteal by the cybersecurity firm.

The Outlook add-in is advertised by its developer as a way to connect different calendars in one place and share their availability via email. The add-in was last updated in December 2022.

See also: Coinbase Cartel: Steals data from major companies

Idan Dardikman, co-founder and CTO of Koi, told The Hacker News that the incident represents a broadening of attack paths in the supply chain.

“This is the same class of attack we’ve seen in browser extensions, npm packages, and IDE plugins: a trusted distribution channel where content can be changed after approval,” Dardikman said. “What makes add-ins particularly worrisome is a combination of factors: they run inside Outlook, where users handle their most sensitive communications, can request permissions to read and modify email , and are distributed through the Microsoft Store, which carries implicit trust.”

“The AgreeTo case adds another dimension: the original developer did nothing wrong. They created a legitimate product and moved on. The attack exploited the gap between the time a developer abandons a project and the time the platform notices it. Any marketplace that hosts remote dynamic dependencies is vulnerable to this.”“.

At its core, the attack exploits the way Office add-ins work and the lack of periodic content monitoring of add-ins published to the Marketplace. According to Microsoft's documentation, add-in developers must create an account and submit their solution to Partner Center. Then, an approval process begins.

See also: Arsink Rat: Steals sensitive data from Android devices

Malicious Outlook add-in stole over 4,000 Microsoft credentials

Additionally, Office add-ins use a manifest file that declares a URL, the contents of which are retrieved and served in real time by the developer's server whenever it is opened within an iframe within the application. However, there is nothing to prevent a malicious actor from taking control of an expired domain.

Malicious Outlook add-in: How did the AgreeTo attack work?

In the case of AgreeTo, the manifest file pointed to a URL hosted on Vercel (“outlook-one.vercel[.]app”), which became available after the developer deleted their Vercel deployment.

The attacker exploited this behavior to set up a phishing kit at this URL, which displayed a fake Microsoft login page , capturing the passwords entered. The credentials were sent to the attacker via the Telegram Bot API, and the victim was eventually redirected to the real Microsoft login page, without realizing it.

But Koi warns that the incident could have been worse. Since the add-on is configured with “ReadWriteItem” permissions – which allow it to read and modify a user’s emails – an attacker could exploit this blind spot to deploy JavaScript that can secretly extract the Inbox a victim’s.

The findings once again highlight the need to reconsider the tools that are uploaded to marketplaces and repositories.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Dardikman said that while Microsoft reviews the manifest during the initial submission phase, there is no control over the actual content that is retrieved live from the developer's server each time the add-on is opened, once it has been signed and approved. As a result, the lack of ongoing monitoring opens the door to unforeseen security risks.

“Office add-ins are fundamentally different from traditional software,” Dardikman added. “They don’t ship a static package of code. The manifest simply declares a URL, and whatever that URL serves at any given time is what is executed within Outlook. In the case of AgreeTo, Microsoft signed the manifest in December 2022, pointing to outlook-one.vercel.app. The same URL now serves a phishing kit , and the add-in is still listed in the store.”

See also: Chrome extensions abuse links and steal access to ChatGPT

Malicious Outlook add-in stole over 4,000 Microsoft credentials

Koi recommends a number of steps Microsoft can take to address the threat:

  • Trigger a re-review when an add-on's URL starts returning different content than it was during the review.
  • Verify domain ownership to ensure it is managed by the add-on developer and flag add-ons where the domain infrastructure has changed hands.
  • Implement a mechanism to delete or flag add-ons that have not been updated beyond a certain period of time.
  • Show installation counts to assess impact.

It's worth noting that the problem isn't limited to the Microsoft Marketplace or the Office Store. Last month, Open VSX announced plans to enforce security checks before publishing Microsoft Visual Studio Code (VS Code) extensions. Microsoft's VS Code Marketplace, similarly, periodically performs a bulk rescan of all packages in the registry.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS