In early February 2026, a malicious Outlook add-in – delivered via a hijacked domain of a previously legitimate add-in – presented a fake Microsoft login page and harvested over 4,000 user credentials in real time.
Organizations in the Microsoft ecosystem using third-party Outlook add-ins.
Abusing trust in a legitimate add-in (supply-chain) bypasses suspicion and yields credentials usable for broad access to sensitive data.
- Audit installed Outlook/Office add-ins and remove untrusted ones.
- Reset credentials for potentially affected users and enforce phishing-resistant MFA.
- Monitor for logins to/from the hijacked add-in domain and anomalous sign-ins.
- Restrict add-in installation via admin policy.
Key Technical Findings
Supply-chain credential-theft via a malicious Outlook add-in.
Microsoft 365 user accounts of organizations using the affected add-in.
Hijacked add-in domain serving a counterfeit login page.
User authenticates on the fake page; credentials captured in real time.
Not specified in the source material.
Not specified in the source material.
Abuse of a trusted, previously legitimate add-in to avoid suspicion.
Real-time capture of Microsoft credentials via the fake login (T1071.001).
Potential broader access using stolen credentials (Potential – requires validation).
Credentials exfiltrated via web protocols to attacker infrastructure.
High – 4,000+ credentials compromised.
Technical Background
Attackers took over the domain associated with a previously legitimate Outlook add-in and used it to serve a counterfeit Microsoft login page. Because the add-in was already trusted and installed, users entered credentials that were captured and exfiltrated over web protocols in real time.
The core weakness is limited visibility into third-party integrations. Defenses center on add-in governance, anomaly detection in sign-in logs, and phishing-resistant MFA that resists credential replay.
Attack Chain Analysis
-
Initial Access
ActivityServe a fake login via the hijacked add-in domain.
EvidenceConnections to the add-in's domain serving a login page.
TelemetryProxy/DNS logs.
Detection opportunityMonitor for anomalous requests/DNS to the add-in domain.
-
Credential Access
ActivityCapture credentials entered on the fake page (T1071.001).
EvidenceLogins from new devices/locations afterward.
TelemetryM365 sign-in logs.
Detection opportunityAlert on impossible travel and new-device logins.
-
Exfiltration
ActivitySend captured credentials to attacker infrastructure.
EvidenceOutbound web requests to attacker host.
TelemetryProxy logs.
Detection opportunityDetect credential POSTs to untrusted domains.
Deep Technical Behavior Analysis
The defining behavior is real-time credential interception through a trusted integration. Because no malware necessarily runs on the endpoint, the clearest signals are network connections to the hijacked add-in domain and subsequent anomalous M365 sign-ins.
Specific domains, the add-in name, and attacker infrastructure are not specified in the source material and require validation.
Indicators of Compromise
Indicators of Behavior
Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).
| Behavioral Indicator | Description | Data Source | Confidence |
|---|---|---|---|
| New SSH authorized_keys / cron entries | Unexpected persistence on Linux hosts. | auditd, /var/log/secure, cron logs | Potential |
| Shell history gaps or clearing | History truncated or redirected to /dev/null. | auditd, bash history | Potential |
| Web shell-like activity | New/modified server-side scripts in writable web paths; anomalous POSTs. | Web access/error logs, FIM | Potential |
| Abnormal 403/404/500 patterns | Enumeration or exploitation attempts against endpoints. | Web server logs, WAF | Potential |
| Beaconing to rare destinations | Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. | Proxy, firewall, DNS logs | Potential |
| Unusual DNS queries | High-entropy or rare domains; possible tunneling. | DNS resolver logs | Potential |
| Authentication anomalies | Spraying/stuffing, impossible travel, or MFA fatigue patterns. | IdP/VPN logs, Azure AD/Okta sign-ins | Potential |
| Suspicious IAM/OAuth changes | New API keys, OAuth apps, service principals, or role grants. | CloudTrail, Azure AD audit, GCP audit | Potential |
Detection Engineering Guidance
Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.
pseudo: periodic outbound (low jitter) to newly-seen domain/IP
with small uniform payloads => alert(level=medium)
Recommended Log Sources
| Platform | Log Source | What to Look For | Priority |
|---|---|---|---|
| Endpoint | EDR / Defender telemetry | Process tree, persistence, tamper attempts | High |
| Web | Web server access logs | Anomalous POSTs, new endpoints, web-shell-like requests | High |
| Web | Web server error logs | Repeated 403/404/500 bursts on single endpoints | Medium |
| Linux | auth.log / secure | SSH logins, sudo, account changes | High |
| Linux | auditd | execve, file writes, persistence paths | High |
| Cloud | CloudTrail / Azure AD / GCP audit | IAM/OAuth changes, key creation, role grants, sign-ins | High |
| Identity | IdP / VPN logs | Impossible travel, spraying, MFA fatigue | High |
| Network | DNS resolver logs | Rare/high-entropy domains, tunneling | Medium |
| Network | Proxy / firewall logs | Beaconing, direct-IP C2, exfil volume | High |
MITRE ATT&CK Mapping
| Tactic | Technique ID | Technique Name | Relevance | Detection Opportunity | Confidence |
|---|---|---|---|---|---|
| Credential Access | T1071.001 | Application Layer Protocol: Web Protocols | Utilizing web protocols to exfiltrate credentials through fake login pages. | Monitor for anomalous web requests and DNS queries. | Reported |
Incident Response Guidance
- Validate exposure and confirm whether the issue applies to your environment.
- Preserve evidence (memory, disk, relevant logs) before remediation.
- Isolate affected hosts/accounts if compromise is suspected.
- Collect volatile data and review the log sources listed above.
- Hunt for the indicators of behavior and any related atomic indicators.
- Rotate potentially exposed credentials, keys, and session tokens.
- Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
- Patch affected systems; reimage where integrity cannot be assured.
- Run post-remediation validation and a BAS/security-validation retest.
Remediation and Hardening
- Patch affected systems and reduce internet-exposed services.
- Enforce MFA and least-privilege for privileged and remote access.
- Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
- Restrict script execution and constrain LOLBins where feasible.
- Monitor persistence locations and disable unnecessary services.
- Segment critical assets and review privileged accounts.
- Rotate secrets and remove credentials from configuration files.
- Tune SIEM/EDR detections, then validate controls after changes.
Business Risk
- Service disruption: degraded or unavailable systems during compromise or recovery.
- Data exposure: risk to sensitive, regulated, or customer data depending on scope.
- Regulatory exposure: potential breach-notification and compliance obligations.
- Financial impact: incident response, downtime, and potential extortion costs.
- Brand and trust impact: reputational damage with customers and partners.
- Identity blast radius: compromised accounts can expand access across cloud and SaaS.
Executive Takeaway
What leadership needs to know: Abusing trust in a legitimate add-in (supply-chain) bypasses suspicion and yields credentials usable for broad access to sensitive data. Current assessed risk: High.
Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.
Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.
Validating Your Defenses with Valitrix
The Valitrix Breach and Attack Simulation (BAS) platform provides organizations with the capability to safely emulate the specific techniques associated with this type of attack. By utilizing MITRE ATT&CK mappings, Valitrix allows security teams to validate their detection and prevention controls against real-world adversary tactics. This continuous validation process ensures that defenses are not only theoretical but proven effective against actual threats.
Through automated simulations that replicate credential theft scenarios similar to those executed by attackers using malicious Outlook add-ins, organizations can identify gaps in their security posture. By addressing these vulnerabilities proactively, businesses can significantly bolster their defenses against future incidents.
Key Takeaways
- The malicious Outlook add-in incident highlights vulnerabilities within legitimate software ecosystems.
- Credential theft can occur rapidly through social engineering and fake login pages.
- User education is crucial in recognizing and mitigating phishing attacks.
- Organizations should prioritize endpoint protection and regular audits of installed software.
Frequently Asked Questions
What is a supply chain attack?
A supply chain attack targets components within a supply chain, exploiting weaker links to gain access to sensitive systems or data.
How can users protect their credentials?
Users should enable two-factor authentication (2FA), remain cautious of suspicious communications or add-ins, and regularly update passwords.
What are signs of a malicious add-in?
Indicators include unexpected behavior such as unusual permission requests or prompts for login credentials that exceed normal functionality.



