Malicious Outlook Add-in Hijacked to Steal 4,000 Microsoft Credentials
Summary
Hide ▲
Show ▼
A legitimate AgreeTo Outlook add-in was hijacked and turned into a phishing kit, stealing over 4,000 Microsoft account credentials. The attackers seized control of an abandoned domain associated with the add-in to serve a fake Microsoft login page. This incident highlights how overlooked and abandoned assets can become attack vectors. The add-in, distributed through Microsoft's store, ran inside Outlook, where users handle sensitive communications. It could request permissions to read and modify emails, exploiting the implicit trust in Microsoft's store. Microsoft has since removed the add-in from its store.
Timeline
-
16.02.2026 14:55 1 articles · 9h ago
AgreeTo Outlook Add-in Hijacked for Phishing Campaign
A legitimate AgreeTo Outlook add-in was hijacked and turned into a phishing kit, stealing over 4,000 Microsoft account credentials. The attackers seized control of an abandoned domain associated with the add-in to serve a fake Microsoft login page. Microsoft has since removed the add-in from its store.
Show sources
- Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware — thehackernews.com — 16.02.2026 14:55
Information Snippets
-
The AgreeTo Outlook add-in was hijacked and turned into a phishing kit.
First reported: 16.02.2026 14:551 source, 1 articleShow sources
- Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware — thehackernews.com — 16.02.2026 14:55
-
Over 4,000 Microsoft account credentials were stolen.
First reported: 16.02.2026 14:551 source, 1 articleShow sources
- Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware — thehackernews.com — 16.02.2026 14:55
-
Attackers seized control of an abandoned domain associated with the add-in.
First reported: 16.02.2026 14:551 source, 1 articleShow sources
- Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware — thehackernews.com — 16.02.2026 14:55
-
The add-in was distributed through Microsoft's store, exploiting implicit trust.
First reported: 16.02.2026 14:551 source, 1 articleShow sources
- Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware — thehackernews.com — 16.02.2026 14:55
-
Microsoft has removed the add-in from its store.
First reported: 16.02.2026 14:551 source, 1 articleShow sources
- Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware — thehackernews.com — 16.02.2026 14:55