Varonis Threat Labs reported an attack technique dubbed Exfil Out&Look that abuses Microsoft 365 Outlook add-ins—particularly in Outlook Web Access (OWA)—to exfiltrate sensitive email content with little to no forensic visibility. The method does not rely on a traditional software vulnerability; instead, it weaponizes legitimate add-in capabilities (manifest-driven HTML/JS apps) to intercept outbound messages via the OnMessageSend event and transmit email data (e.g., subject, body, recipients) to attacker-controlled infrastructure, potentially using only minimal permissions such as ReadWriteItem that may avoid higher-friction consent prompts.
A key risk highlighted is a logging and accountability gap: OWA may not generate Unified Audit Log entries for add-in installation or execution, enabling persistence and “zero-trace” operation in environments that depend on Microsoft 365 audit telemetry for detection and investigations. Varonis stated it reported the issue to Microsoft via MSRC (Sept. 30, 2025) and that Microsoft categorized it as a low-severity product issue with no immediate fix planned; as a result, defenders may need to focus on governance and control of add-ins (e.g., restricting add-in installation sources and permissions) rather than expecting a near-term patch.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Varonis publicly disclosed the 'Exfil Out&Look' technique, showing that a malicious Outlook add-in can hook message-send events, capture outbound email data, and transmit it to an external server with minimal permissions and little to no forensic visibility. The research highlighted that OWA-based add-in installs lack corresponding Unified Audit Log entries, while desktop Outlook leaves only a local Windows Event Viewer artifact.
Varonis Threat Labs reported to Microsoft's Security Response Center that Outlook add-ins installed via Outlook Web Access could be abused for stealthy email exfiltration because installation and execution were not captured in Microsoft 365 Unified Audit Logs. Microsoft reportedly classified the issue as a low-severity product bug or suggestion and did not plan an immediate fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcevaronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.