Executive SummaryRisk level: High
What happened

In early February 2026, a malicious Outlook add-in – delivered via a hijacked domain of a previously legitimate add-in – presented a fake Microsoft login page and harvested over 4,000 user credentials in real time.

Who is affected

Organizations in the Microsoft ecosystem using third-party Outlook add-ins.

Why it matters

Abusing trust in a legitimate add-in (supply-chain) bypasses suspicion and yields credentials usable for broad access to sensitive data.

Immediate recommended actions

  • Audit installed Outlook/Office add-ins and remove untrusted ones.
  • Reset credentials for potentially affected users and enforce phishing-resistant MFA.
  • Monitor for logins to/from the hijacked add-in domain and anomalous sign-ins.
  • Restrict add-in installation via admin policy.
How to read this report. Items are labelled by confidence: Confirmed stated as fact in the source, Reported described by the source, Potential analyst inference, and Requires Validation to be confirmed in your environment. Where the source lacks detail this is stated as “Not specified in the source material”.

Key Technical Findings

Vulnerability / Campaign Type

Supply-chain credential-theft via a malicious Outlook add-in.

Affected Systems

Microsoft 365 user accounts of organizations using the affected add-in.

Initial Access Vector

Hijacked add-in domain serving a counterfeit login page.

Execution Method

User authenticates on the fake page; credentials captured in real time.

Persistence

Not specified in the source material.

Privilege Escalation

Not specified in the source material.

Defense Evasion

Abuse of a trusted, previously legitimate add-in to avoid suspicion.

Credential Access

Real-time capture of Microsoft credentials via the fake login (T1071.001).

Lateral Movement

Potential broader access using stolen credentials (Potential – requires validation).

Data Exfiltration

Credentials exfiltrated via web protocols to attacker infrastructure.

Impact Level

High – 4,000+ credentials compromised.

Technical Background

Attackers took over the domain associated with a previously legitimate Outlook add-in and used it to serve a counterfeit Microsoft login page. Because the add-in was already trusted and installed, users entered credentials that were captured and exfiltrated over web protocols in real time.

The core weakness is limited visibility into third-party integrations. Defenses center on add-in governance, anomaly detection in sign-in logs, and phishing-resistant MFA that resists credential replay.

Attack Chain Analysis

  1. Initial Access

    ActivityServe a fake login via the hijacked add-in domain.

    EvidenceConnections to the add-in's domain serving a login page.

    TelemetryProxy/DNS logs.

    Detection opportunityMonitor for anomalous requests/DNS to the add-in domain.

  2. Credential Access

    ActivityCapture credentials entered on the fake page (T1071.001).

    EvidenceLogins from new devices/locations afterward.

    TelemetryM365 sign-in logs.

    Detection opportunityAlert on impossible travel and new-device logins.

  3. Exfiltration

    ActivitySend captured credentials to attacker infrastructure.

    EvidenceOutbound web requests to attacker host.

    TelemetryProxy logs.

    Detection opportunityDetect credential POSTs to untrusted domains.

Deep Technical Behavior Analysis

The defining behavior is real-time credential interception through a trusted integration. Because no malware necessarily runs on the endpoint, the clearest signals are network connections to the hijacked add-in domain and subsequent anomalous M365 sign-ins.

Specific domains, the add-in name, and attacker infrastructure are not specified in the source material and require validation.

Indicators of Compromise

No indicators of compromise were provided in the source material.

Indicators of Behavior

Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).

Behavioral Indicator Description Data Source Confidence
New SSH authorized_keys / cron entries Unexpected persistence on Linux hosts. auditd, /var/log/secure, cron logs Potential
Shell history gaps or clearing History truncated or redirected to /dev/null. auditd, bash history Potential
Web shell-like activity New/modified server-side scripts in writable web paths; anomalous POSTs. Web access/error logs, FIM Potential
Abnormal 403/404/500 patterns Enumeration or exploitation attempts against endpoints. Web server logs, WAF Potential
Beaconing to rare destinations Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. Proxy, firewall, DNS logs Potential
Unusual DNS queries High-entropy or rare domains; possible tunneling. DNS resolver logs Potential
Authentication anomalies Spraying/stuffing, impossible travel, or MFA fatigue patterns. IdP/VPN logs, Azure AD/Okta sign-ins Potential
Suspicious IAM/OAuth changes New API keys, OAuth apps, service principals, or role grants. CloudTrail, Azure AD audit, GCP audit Potential

Detection Engineering Guidance

Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.

T1071.001 — Application Layer Protocol: Web Protocols
  • ObjectiveDetect C2 over web protocols
  • Suspicious patternBeaconing to rare destinations
  • Data sourceProxy, firewall, DNS
  • False positivesAdmin tooling/automation; baseline before alerting.
  • ResponseTriage host, validate scope, preserve evidence, contain if confirmed.
pseudo: periodic outbound (low jitter) to newly-seen domain/IP
  with small uniform payloads => alert(level=medium)
Platform Log Source What to Look For Priority
Endpoint EDR / Defender telemetry Process tree, persistence, tamper attempts High
Web Web server access logs Anomalous POSTs, new endpoints, web-shell-like requests High
Web Web server error logs Repeated 403/404/500 bursts on single endpoints Medium
Linux auth.log / secure SSH logins, sudo, account changes High
Linux auditd execve, file writes, persistence paths High
Cloud CloudTrail / Azure AD / GCP audit IAM/OAuth changes, key creation, role grants, sign-ins High
Identity IdP / VPN logs Impossible travel, spraying, MFA fatigue High
Network DNS resolver logs Rare/high-entropy domains, tunneling Medium
Network Proxy / firewall logs Beaconing, direct-IP C2, exfil volume High

MITRE ATT&CK Mapping

Tactic Technique ID Technique Name Relevance Detection Opportunity Confidence
Credential Access T1071.001 Application Layer Protocol: Web Protocols Utilizing web protocols to exfiltrate credentials through fake login pages. Monitor for anomalous web requests and DNS queries. Reported

Incident Response Guidance

  • Validate exposure and confirm whether the issue applies to your environment.
  • Preserve evidence (memory, disk, relevant logs) before remediation.
  • Isolate affected hosts/accounts if compromise is suspected.
  • Collect volatile data and review the log sources listed above.
  • Hunt for the indicators of behavior and any related atomic indicators.
  • Rotate potentially exposed credentials, keys, and session tokens.
  • Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
  • Patch affected systems; reimage where integrity cannot be assured.
  • Run post-remediation validation and a BAS/security-validation retest.

Remediation and Hardening

  • Patch affected systems and reduce internet-exposed services.
  • Enforce MFA and least-privilege for privileged and remote access.
  • Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
  • Restrict script execution and constrain LOLBins where feasible.
  • Monitor persistence locations and disable unnecessary services.
  • Segment critical assets and review privileged accounts.
  • Rotate secrets and remove credentials from configuration files.
  • Tune SIEM/EDR detections, then validate controls after changes.

Business Risk

  • Service disruption: degraded or unavailable systems during compromise or recovery.
  • Data exposure: risk to sensitive, regulated, or customer data depending on scope.
  • Regulatory exposure: potential breach-notification and compliance obligations.
  • Financial impact: incident response, downtime, and potential extortion costs.
  • Brand and trust impact: reputational damage with customers and partners.
  • Identity blast radius: compromised accounts can expand access across cloud and SaaS.

Executive Takeaway

What leadership needs to know: Abusing trust in a legitimate add-in (supply-chain) bypasses suspicion and yields credentials usable for broad access to sensitive data. Current assessed risk: High.

Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.

Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.

Validating Your Defenses with Valitrix

The Valitrix Breach and Attack Simulation (BAS) platform provides organizations with the capability to safely emulate the specific techniques associated with this type of attack. By utilizing MITRE ATT&CK mappings, Valitrix allows security teams to validate their detection and prevention controls against real-world adversary tactics. This continuous validation process ensures that defenses are not only theoretical but proven effective against actual threats.

Through automated simulations that replicate credential theft scenarios similar to those executed by attackers using malicious Outlook add-ins, organizations can identify gaps in their security posture. By addressing these vulnerabilities proactively, businesses can significantly bolster their defenses against future incidents.

Key Takeaways

  • The malicious Outlook add-in incident highlights vulnerabilities within legitimate software ecosystems.
  • Credential theft can occur rapidly through social engineering and fake login pages.
  • User education is crucial in recognizing and mitigating phishing attacks.
  • Organizations should prioritize endpoint protection and regular audits of installed software.

Frequently Asked Questions

What is a supply chain attack?

A supply chain attack targets components within a supply chain, exploiting weaker links to gain access to sensitive systems or data.

How can users protect their credentials?

Users should enable two-factor authentication (2FA), remain cautious of suspicious communications or add-ins, and regularly update passwords.

What are signs of a malicious add-in?

Indicators include unexpected behavior such as unusual permission requests or prompts for login credentials that exceed normal functionality.