365-Stealer is a tool referenced in attack-simulation content for emulating Microsoft 365 and Azure AD OAuth consent grant abuse. The provided content states it was used together with a multi-tenant application registration to simulate consent grant attacks mapped to MITRE ATT&CK T1528 (Steal Application Access Token). In these simulations, 365-Stealer was used across multiple scenarios involving Office 365 and Azure AD user consent events, including user consent granted, consent declined, consent blocked, mail-permission consent, and file-permission consent. The content ties its use to Microsoft 365/Azure AD environments and related telemetry sources such as Office 365 management activity logs (sourcetype o365:management:activity) and Azure Monitor AAD logs (sourcetype azure:monitor:aad). The material references Altered Security’s blog and GitHub repository for 365-Stealer. High-confidence behavior directly stated in the content is limited to its use for simulating OAuth application consent attacks via multi-tenant app registration; no additional verified malware capabilities, infection vector, persistence mechanism, or specific IOCs are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
References https://www.alteredsecurity.com/post/introduction-to-365-stealer ... https://github.com/AlteredSecurity/365-Stealer
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named tool associated with Microsoft 365/OAuth abuse context; the content does not provide direct behavioral details beyond the reference.
A Microsoft 365-focused stealer referenced in the context of malicious OAuth application consent and account compromise.
A tool/malware referenced in the context of Office 365 abuse, associated with stealing or accessing Microsoft 365 data via OAuth application consent and mail-related permissions.
An OAuth-focused stealer tool referenced in the context of risky or malicious Office 365 application consent and token theft scenarios.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.