Researchers reported the first known malicious Microsoft Outlook add-in, dubbed AgreeToSteal, being used to harvest more than 4,000 Microsoft account credentials. The add-in abused Outlook’s extensibility model to present credential-stealing prompts inside a trusted email client environment, giving attackers a convincing way to capture usernames and passwords tied to Microsoft services.
The campaign highlights a new phishing and account-theft vector that moves beyond malicious documents and browser-based lures into enterprise productivity software itself. Security reporting said the add-in was discovered in the wild and linked to large-scale credential theft, underscoring the need for organizations to scrutinize Outlook add-ins, restrict unauthorized extensions, and monitor Microsoft account activity for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Koi Security reported discovering AgreeToSteal, described as the first malicious Outlook add-in, which impersonated Adobe Acrobat and abused OAuth permissions to steal Microsoft credentials. The campaign was linked to more than 4,000 stolen credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.