Attackers with access to a Microsoft 365 identity or app context can accelerate post-compromise reconnaissance and data discovery by using built-in AI assistants and Microsoft Graph at scale. Varonis warns that Microsoft 365 Copilot inherits the logged-in user’s permissions, turning a compromised account (e.g., via phishing kits) into a natural-language interface for quickly locating sensitive content across SharePoint, OneDrive, and Exchange; this can reduce the volume and distribution of traditional “click-by-click” access events and shift activity into Copilot query patterns, changing the forensic footprint defenders typically rely on.
Separately, a red-team toolkit called M365Pwned was released as two PowerShell 5.1 WinForms GUI tools—MailPwned-GUI.ps1 (Exchange Online/Outlook) and SharePwned-GUI.ps1 (SharePoint/OneDrive)—that enumerate, search, and exfiltrate tenant data using the Microsoft Graph API with application-level OAuth (admin-consented) permissions and authentication via client secret, certificate thumbprint, or raw access token (“pass-the-token”). The tooling highlights how application permissions can enable broad tenant-wide mailbox and file access (e.g., global keyword searches, bulk attachment downloads, document preview/download, and impersonation email composition), reinforcing the risk that over-permissioned identities/apps and weak governance in M365 can turn post-compromise recon into fast, high-impact data access.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Varonis Threat Labs disclosed a demonstration called 'Reprompt,' described as a single-click Copilot attack that exfiltrates personal data by hijacking an authenticated session and relaying requests through an attacker-controlled server. The disclosure highlighted how AI assistants can be abused after account compromise to speed discovery and data theft.
Varonis published analysis arguing that Microsoft 365 Copilot can materially change post-compromise reconnaissance by allowing attackers with stolen credentials or session tokens to query and summarize data the compromised user can access across SharePoint, OneDrive, Exchange, and Teams. The report framed oversharing and excessive permissions in Microsoft 365 as the core risk and recommended least-privilege enforcement and tighter data access controls.
A red teamer using the handle OtterHacker publicly released M365Pwned, a pair of PowerShell WinForms GUI tools for enumerating, searching, and exfiltrating Microsoft 365 data through the Microsoft Graph API using application-level OAuth tokens. The release included MailPwned for Exchange Online/Outlook and SharePwned for SharePoint/OneDrive, with support for multiple authentication methods and sovereign/GCC cloud routing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.