A legitimate Microsoft Outlook meeting-scheduling add-in, AgreeTo, was hijacked after its developer abandoned the project and the add-in’s backend Vercel URL (outlook-one.vercel.app) expired and was later re-registered by a threat actor. Because Office add-ins are effectively signed XML manifests that load a developer-controlled URL in an iframe, Microsoft’s review/signing process validated the manifest at submission time but did not continuously verify what the referenced URL served afterward. The attacker leveraged the add-in’s previously approved ReadWriteItem permissions (appropriate for scheduling, but powerful if abused) to present a convincing in-client phishing experience inside Outlook’s sidebar.
Researchers reported the attacker deployed a multi-step phishing kit (fake Microsoft sign-in, credential/password capture, exfiltration, and redirect to the legitimate login.microsoftonline.com) and exfiltrated data via a Telegram bot/channel, including 4,000+ Microsoft account credentials as well as credit card numbers and banking security answers. The Chrome extension associated with the project had already been removed earlier after becoming defunct, but the Outlook add-in remained listed in the Office Add-in Store until it was discovered and subsequently removed; investigators also observed the actor actively testing stolen credentials during analysis.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft removed the malicious AgreeTo add-in from the Microsoft Office Add-in Store on the day the reporting was published. The removal followed disclosure that the add-in had been hijacked to serve phishing content and abuse its existing permissions.
Koi Security published its findings on the malicious add-in, described it as the first known malicious Outlook add-in seen in the wild, and said it notified affected victims where possible. The researchers also submitted abuse and takedown reports to Microsoft, Vercel, and Telegram.
The hijacked add-in displayed a fake Microsoft sign-in page inside Outlook's trusted sidebar, harvested credentials, and exfiltrated them through Telegram along with some payment and banking data. Investigators later recovered evidence of more than 4,000 victim accounts and linked the activity to a broader multi-brand phishing operation.
After the developer abandoned the add-in and its Vercel-hosted backend URL lapsed, a threat actor re-registered or reclaimed the orphaned Vercel location. The attacker replaced the legitimate content with a phishing kit while the approved add-in remained in Microsoft's store.
The legitimate AgreeTo meeting-scheduling Outlook add-in was listed in the Microsoft Office Add-in Store in December 2022. Its manifest was approved by Microsoft and pointed Outlook to load remote content from developer-controlled infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemalwarebytes.com
Open sourcebleepingcomputer.com
Open sourcekoi.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.