Attackers are increasingly using malicious Microsoft 365 mailbox rules after account compromise to silently forward, delete, hide, or mark emails as read, turning native email features into a persistence and surveillance mechanism. Reports citing Proofpoint found the technique in a significant share of compromised tenants, with some rules created within seconds of initial access, and warned that the rules can suppress MFA prompts, password reset messages, and security alerts while enabling continued monitoring of sensitive business communications.
The abuse typically follows credential phishing, password spraying, or OAuth consent attacks, and can persist even after password resets or MFA enrollment unless the rules are explicitly removed. Researchers said the method has featured in business email compromise and payroll fraud cases, including schemes using spoofed homoglyph domains and external mail services, and recommended auditing and deleting unauthorized inbox rules, disabling automatic external forwarding, revoking active sessions and refresh tokens, reviewing OAuth app permissions, and checking Entra ID sign-in logs for suspicious activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting described attackers creating malicious mailbox rules within seconds of account takeover and cited a payroll fraud case involving a hidden rule, a spoofed homoglyph domain, and Zoho. The reporting also emphasized common initial access vectors such as credential phishing, password spraying, and OAuth consent abuse.
Security researchers and practitioners highlighted that malicious Microsoft 365 mailbox rules can remain active even after password resets and MFA enrollment unless explicitly removed. This made the technique a recurring concern in business email compromise investigations because attackers could maintain access to sensitive email flows without direct login access.
Proofpoint reported that malicious mailbox rules were commonly created shortly after Microsoft 365 account compromise during Q4 2025. The rules were used for persistence, surveillance, and email exfiltration, including hiding security alerts and forwarding sensitive messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.