First malicious plugin invades Microsoft Win10/Win11 App Store, over 4,000 users affected

IT Home, February 12 — Technology media BleepingComputer published a blog post yesterday (February 11), reporting that the Outlook plugin AgreeTo on the Microsoft Store has been hijacked and turned into a phishing tool, resulting in the leak of credentials for over 4,000 accounts.

The plugin was released by an independent developer. Since its launch in December 2022, the project was abandoned, leading to its URL hosted on Vercel being taken over by attackers, who embedded malicious code.

Because Microsoft no longer conducts follow-up verification after the plugin is published, attackers exploited this loophole by deploying fake login pages, password collection scripts, and data leakage programs on the abandoned URL.

When users open this malicious plugin, the Outlook sidebar displays a fake Microsoft account login interface, which is highly deceptive. The credentials entered by users are sent in real-time to the attacker via the Telegram Bot API. The victim is then redirected to the real login page to reduce suspicion.

Koi Security researcher Oren Yomtov pointed out that this is the first malicious software on the official Microsoft app store and the first Outlook malicious plugin detected in a real environment.

Before IT Home published this report, Microsoft had already removed the plugin. Experts recommend that users who installed AgreeTo uninstall it immediately and reset their passwords.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)