AgreeTo Malicious Outlook Add-In - Remove Spyware & Malware with SpyHunter - EnigmaSoft Ltd

General News

Summary

Researchers discovered a malicious Microsoft Outlook add-in campaign called AgreeToSteal that hijacked an abandoned but signed add-in (AgreeTo) to serve a phishing kit and harvest over 4,000 Microsoft credentials. The attacker seized an expired Vercel-hosted URL referenced in the add-in manifest, served a counterfeit login page, exfiltrated passwords via the Telegram Bot API, and then redirected victims to the real sign-in page to avoid detection. The incident exploited a structural weakness in Office add-ins: manifests reference live URLs that Microsoft signs once but do not continuously validate, allowing remote content to change after approval. Security experts recommend continuous monitoring, domain ownership validation, automatic re-reviews, and delisting or warning mechanisms for abandoned add-ins to mitigate similar supply-chain risks.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M