Tag: Malicious Outlook

First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials
News

First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials

Researchers studying cybersecurity have found what they claim to be the first malicious Microsoft Outlook add-in ever found in the wild. An unidentified attacker used the domain linked to a now-defunct genuine add-in to host a phony Microsoft login page in this interesting supply chain assault, which Koi Security described. In the process, they stole over 4,000 passwords. The cybersecurity firm has given the action the codename AgreeToSteal. AgreeTo is the Outlook add-in in question. According to its developer, it allows users to link several calendars in one location and communicate their availability via email. In December 2022, the add-in received its most recent update. Koi's co-founder and CTO, Idan Dardikman, told The Hacker News that the incident shows that supply chain at...