AgreeTo is a maliciously hijacked Microsoft Outlook add-in that was originally a legitimate meeting-scheduling tool listed in the Microsoft Office Add-in Store since December 2022. After the developer abandoned the project and its Vercel-hosted URL, a threat actor reclaimed the orphaned Vercel location and replaced the add-in’s remote content with a phishing kit. Because Office add-ins load web content from developer-controlled infrastructure, the attacker-controlled content was rendered inside Outlook’s trusted sidebar while the add-in remained listed in Microsoft’s official store.
The malicious AgreeTo add-in displayed a fake Microsoft sign-in page inside Outlook, collected credentials, and then redirected victims to the legitimate Microsoft login page to reduce suspicion. Reported kit components included a fake Microsoft login page, a password collection page, an exfiltration script, and a redirect. Stolen data was exfiltrated via a Telegram bot API. Koi Security reported recovering evidence of an active operation involving more than 4,000 stolen Microsoft account credentials, as well as credit card numbers and banking security answers. The operator was reportedly testing stolen credentials in real time.
The infection vector was use of the compromised add-in itself rather than phishing emails or malicious links. The campaign benefited from hosting on a legitimate vercel.app domain and execution within the Outlook process, which reportedly helped bypass common controls such as email gateways, endpoint protection, and URL filtering. AgreeTo retained ReadWriteItem permissions, meaning the attacker could potentially read and modify victim emails, although no confirmed email tampering was reported. Koi Security described the incident as exposing a structural weakness in the Office add-in model, where Microsoft reviews and signs the manifest at submission but the remotely hosted runtime content can later change without further review. Microsoft reportedly removed the add-in from the store on the day of reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate Microsoft Outlook/Office add-in (meeting scheduling tool) that was effectively hijacked via takeover of its abandoned Vercel-hosted URL, turning it into an in-client phishing/credential-harvesting page (fake Microsoft login) served inside Outlook’s sidebar; researchers observed theft of Microsoft credentials and other sensitive data, with potential for email read/modify due to ReadWriteItem permissions.
A legitimate Outlook meeting-scheduling add-in that was hijacked after its orphaned Vercel-hosted URL was taken over by a threat actor. The attacker replaced the add-in’s hosted content with a fake Microsoft sign-in flow (login page, password collection, exfiltration script, redirect) to steal Microsoft account credentials and other sensitive data, exfiltrating via the Telegram Bot API and then redirecting victims to the real Microsoft login page to reduce suspicion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.