×
outlook add in credential theft

Microsoft Store Outlook Add-in Exploited in Major Credential Theft of 4,000 Accounts

Over 4,000 Microsoft accounts fell victim to the “AgreeToSteal” attack after threat actors hijacked an abandoned Outlook add-in called AgreeTo, transforming the legitimate productivity tool into a credential-harvesting machine. The attackers claimed the developer’s abandoned Vercel-hosted URL and replaced the original functionality with a sophisticated phishing kit that captured usernames, passwords, and even banking details through Telegram’s bot API. Microsoft’s post-approval monitoring gap permitted the malicious changes to slip through undetected, exposing a critical flaw in the Office add-in model where developers provide only XML manifests without ongoing code verification—a vulnerability that reveals how trusted distribution channels can become weaponized attack vectors.

When a legitimate developer abandons a project, attackers don’t just inherit code—they inherit trust. This is precisely what transpired with AgreeTo, an Outlook add-in that quietly morphed from a scheduling tool into a credential-stealing machine after its original developer walked away in December 2022.

The attack, dubbed “AgreeToSteal” by Koi Security researchers, exploited a significant vulnerability in Microsoft’s add-in ecosystem. Upon the legitimate developer abandoning the project, they also left behind the Vercel-hosted URL (outlook-one.vercel.app) that powered the add-in. A threat actor simply claimed the orphaned domain and replaced the original functionality with a sophisticated phishing kit.

Attackers claimed an abandoned Vercel domain to transform a legitimate Outlook add-in into a credential-harvesting operation hiding behind Microsoft’s trusted storefront.

The kicker? The add-in remained listed in the Microsoft Store, ready for unsuspecting users to install.

Here’s where it gets interesting. Instead of displaying the legitimate scheduling interface, the compromised add-in presented users with a convincing fake Microsoft login page right in their Outlook sidebar. Credentials entered by victims were automatically funneled to the attacker via Telegram’s bot API—no complex command-and-control infrastructure needed.

After submitting their information, victims were redirected to the genuine login.microsoftonline.com page, reducing suspicion and maintaining the operation’s smooth running.

The four-page phishing kit captured more than just usernames and passwords. Credit card numbers, CVVs, PINs, and banking security answers flowed into the attacker’s poorly secured Telegram channel. Over 4,000 Microsoft accounts were compromised before researchers uncovered the operation.

The threat actor was actively testing stolen credentials while researchers examined the breach, demonstrating the real-time nature of the attack. This wasn’t an isolated effort either—the same actor controlled at least 12 distinct phishing kits targeting ISPs, banks, and webmail providers.

The root cause? The Microsoft Store has no ongoing content verification after initial approval. When developers submit an add-in, they provide a simple XML manifest containing the name, description, URL, and requested permissions—but never the actual code.

Microsoft reviews and signs the manifest once, then never monitors the content loaded from developer-controlled URLs. Malicious changes can occur post-approval without triggering any review.

The AgreeTo add-in held “ReadWriteItem” permissions, granting read and modify access to user emails. Although researchers found no evidence the attacker exploited these capabilities, the potential for covert mailbox exfiltration existed throughout the campaign. The add-in had advertised itself as connecting calendars and sharing availability before the domain takeover.

That represents a critical security gap in the Office add-in model.

The incident exposes how trust mechanisms designed for convenience become attack vectors when oversight fails. Microsoft’s hands-off approach to post-approval monitoring created an environment where abandoned projects became weaponised distribution channels. This marks the first documented case of malware being hosted on the Microsoft Marketplace.

Until verification extends beyond initial submission, the Store remains vulnerable to supply chain attacks hiding in plain sight.

Final Thoughts

The recent breach involving the Microsoft Store Outlook Add-in serves as a stark reminder that even trusted platforms can fall victim to exploitation. While Microsoft acted quickly to mitigate the impact, the compromise of 4,000 accounts underscores the need for vigilance in our digital environments. Organizations must rigorously audit third-party add-ins, just as they do their core infrastructure, to ensure both convenience and security are maintained.

At Moreton Bay Computer Repairs, we understand the importance of safeguarding your digital assets. Our team can assist you in evaluating and securing your third-party applications, ensuring your organization remains protected against potential threats. Don’t wait for a breach to happen—take proactive steps to secure your data.

For more information on how we can help, click on our Contact Us page to get in touch!

(07) 3144 6766