Threat reportSupply ChainTL-2026-0077

Rogue AgreeTo Outlook Add-In: Abandoned Extension Hijacked Into Supply Chain Phishing Kit — 4,000+ Credentials and Payment Data Stolen

highRESOLVED

Rogue AgreeTo Outlook Add-In (TL-2026-0077) is a high-severity supply-chain compromise, first published 2026-02-12. It has no confirmed attribution, maps to 31 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 12 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
0Not attributed
Detection rules
12SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0077

Threat ID
TL-2026-0077
Severity
HIGH
Status
RESOLVED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
All Sectors
Target regions
North America, Global
Detection rules
12
Indicators of compromise
30

How Rogue AgreeTo Outlook Add-In works

AgreeTo, a legitimate Microsoft Outlook add-in for meeting scheduling published in December 2022, was abandoned by its developer and subsequently hijacked by a cybercriminal who claimed the orphaned Vercel subdomain (outlook-one.vercel.app) to deploy a phishing kit inside Outlook's trusted sidebar. The attack exploited a structural flaw in Microsoft's Office Add-in architecture: add-ins are remote URLs loaded in iframes, and Microsoft reviews the manifest at submission but never re-validates what the URL serves afterward. The attacker harvested 4,000+ Microsoft account credentials, credit card numbers, CVVs, PINs, and banking security answers, exfiltrating data via Telegram Bot API. The same attacker operates at least 12 distinct phishing kits targeting Canadian ISPs, banks, and webmail providers — a professional multi-brand phishing operation. The AgreeTo add-in retained ReadWriteItem permissions (read and modify user emails) from its original legitimate review, meaning the attacker could have silently read inboxes, exfiltrated messages, or sent phishing from victims' accounts. Discovered by Koi Security, reported by Malwarebytes. Infrastructure is LIVE as of publication.

THE FIRST KNOWN MALICIOUS MICROSOFT OUTLOOK ADD-IN DETECTED IN THE WILD

This attack represents a novel supply chain vector: the weaponization of abandoned Office add-ins through URL takeover. It exploits a fundamental architectural flaw in how Microsoft distributes and maintains trust for Office add-ins.

ATTACK CHAIN:

1. LEGITIMATE ORIGIN (Dec 2022): A developer built AgreeTo, an open-source meeting scheduling tool with a Chrome extension (1,000 users, 4.71-star rating, 21 reviews) and an Outlook add-in. Published to Microsoft's Office Add-in Store with ReadWriteItem permissions (read and modify user emails). Microsoft reviewed the XML manifest, signed it, and listed it. The manifest pointed to outlook-one.vercel.app.

2. ABANDONMENT (May 2023): Developer stopped maintaining AgreeTo. Last Chrome extension update: May 2023. Developer's domain (agreeto.app) expired. By July 2024, users were leaving reviews: 'Did this app die? No longer works.' Google removed the dead Chrome extension in February 2025. But the Outlook add-in stayed listed in Microsoft's Office Store.

3. URL TAKEOVER: The developer's Vercel deployment was deleted. The subdomain outlook-one.vercel.app became claimable. An attacker registered the subdomain and deployed a four-page phishing kit: (1) fake Microsoft sign-in page, (2) password collection page, (3) Telegram-based exfiltration script, (4) redirect to real login.microsoftonline.com.

4. PHISHING DELIVERY: When victims opened AgreeTo in Outlook, they saw what appeared to be a normal Microsoft sign-in inside Outlook's trusted sidebar. Credentials were captured via a JavaScript fetch() call to the attacker's Telegram bot (with IP data), then victims were redirected to the real Microsoft login. Seamless — victims assumed they needed to sign in again.

ARCHITECTURAL FLAW: Office add-ins are NOT installed code. They are URLs. A developer submits an XML manifest to Microsoft that says 'load this URL in an iframe inside Outlook.' Microsoft reviews the manifest once at submission but NEVER checks what the URL serves again. The actual content — UI, logic, everything — is fetched live from the developer's server every time the add-in opens. If someone else takes control of that URL, they control what every user sees — inside Outlook's trusted sidebar, with whatever permissions were originally granted.

WHY EXISTING SECURITY TOOLS MISS THIS: - Email security gateways: phishing page doesn't arrive via email - Endpoint protection: JavaScript running inside a legitimate Microsoft process (Outlook) - URL filtering: hosted on vercel.app, which serves millions of legitimate applications - Static analysis: no installed binary to scan — content is fetched dynamically

SCALE AND OPERATOR PROFILE: - 4,000+ stolen credential sets recovered by Koi Security - Credit card numbers, CVVs, PINs, and banking security answers also stolen - Interac e-Transfer payment interception (Canadian banking) - At least 12 distinct phishing kits operated by same attacker, each impersonating different brands (Canadian ISPs, banks, webmail) - Professional multi-brand phishing operation — AgreeTo was one distribution channel - Campaign is STILL ACTIVE — new victims being compromised by the hour - Attacker's exfiltration infrastructure was poorly secured (Koi accessed Telegram channel) - Attacker was actively testing stolen credentials as of publication date

UNEXPLOITED POTENTIAL (ReadWriteItem): The AgreeTo manifest declared ReadWriteItem permissions — the add-in can read AND modify the user's emails. The attacker only used it for a simple phishing page, but the permissions would have allowed: (1) silently reading the victim's entire inbox, (2) exfiltrating sensitive messages, (3) sending phishing emails FROM the victim's own account, (4) creating forwarding rules. The full potential of this attack vector was NOT exploited.

PRIOR RESEARCH: MDSec flagged Office add-ins as an attack surface in 2019, demonstrating how they could be weaponized for persistent mailbox access. Their warning: 'Microsoft also allow developers to push these add-ins to a store, where users can install them. I'm sure you can see the potential problem there.' Seven years later, AgreeTo is exactly the scenario they predicted.

MITRE ATT&CK techniques used in TL-2026-0077

collection

T1005 Data from Local System; T1056 Input Capture; T1114 Email Collection; T1119 Automated Collection; T1213 Data from Information Repositories

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1127 Trusted Developer Utilities Proxy Execution

exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

discovery

T1069 Permission Groups Discovery; T1087 Account Discovery

persistence

T1137 Office Application Startup; T1176 Software Extensions

initial-access

T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

impact

T1531 Account Access Removal

credential-access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

defense-impairment

T1553 Subvert Trust Controls

resource-development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities

reconnaissance

T1594 Search Victim-Owned Websites; T1596 Search Open Technical Databases

Remediation for Rogue AgreeTo Outlook Add-In

Patches

  • No CVE — architectural design flaw in Microsoft Office Add-in trust model, not a traditional vulnerability
  • Microsoft needs to implement: (1) continuous monitoring of add-in URLs, (2) domain ownership verification, (3) automatic delisting of add-ins pointing to expired/changed domains

Immediate actions

  • Uninstall the AgreeTo Outlook add-in immediately (Add-in ID: WA200004949)
  • Change Microsoft account passwords for any user who had AgreeTo installed after May 2023
  • If passwords were reused on other services, change those as well — make each unique
  • Review recent sign-ins and security activity on Microsoft accounts for unknown locations/devices
  • Scan mailboxes for abuse indicators: messages you didn't send, auto-forwarding rules, password-reset emails for other services
  • Monitor payment statements for unauthorized transactions — especially small test charges and e-Transfer fraud

Workarounds

  • Block all Office add-ins via Group Policy or Microsoft 365 admin until audit is complete
  • Use Conditional Access policies to restrict add-in installation to managed devices only
  • Deploy FIDO2/phishing-resistant MFA — stolen passwords alone cannot compromise accounts
  • Monitor Telegram API traffic from corporate networks as potential exfiltration channel

Longer-term hardening

  • Audit ALL Office add-ins installed across the organization — identify abandoned or unused add-ins
  • Implement allow-listing for Office add-ins via Microsoft 365 admin center — block user-installed add-ins
  • Deploy add-in governance policy: only IT-approved add-ins permitted, regular review cycle
  • Monitor for subdomain takeover vulnerabilities across all cloud platforms (Vercel, Netlify, GitHub Pages, Azure)
  • Implement continuous monitoring of installed add-ins, extensions, and plugins for behavioral changes
  • Push for Microsoft to implement continuous URL content validation for Office add-ins, not just one-time manifest review

Weaknesses (CWE) in Rogue AgreeTo Outlook Add-In

CWE-324, CWE-345, CWE-494, CWE-829

Timeline of Rogue AgreeTo Outlook Add-In

  • MDSec publishes research on Office add-ins as an attack surface, warning that Microsoft's store distribution of URL-based add-ins creates a potential weaponization vector. Demonstrates persistent mailbox access via malicious add-ins. Warning goes unheeded for 7 years. Source: https://www.mdsec.co.uk/2019/01/abusing-office-web-add-ins-for-fun-and-limited-profit/
  • Developer publishes AgreeTo to Microsoft Office Add-in Store — a legitimate open-source meeting scheduling tool. Microsoft reviews XML manifest, signs it, grants ReadWriteItem permissions (read/modify user emails), and lists it. Manifest points to outlook-one.vercel.app. Chrome extension also published (1,000 users, 4.71 stars). Source: Koi Security
  • Last Chrome extension update for AgreeTo. Developer stops maintaining the project. Domain agreeto.app eventually expires. The Outlook add-in remains listed in Microsoft's store pointing to the now-unmaintained Vercel URL. Source: Koi Security
  • Users begin leaving reviews on dead Chrome extension: 'Did this app die? No longer works. Makes you login and goes to a GoDaddy holding page.' Microsoft takes no action on the Outlook add-in despite clear signals the developer has abandoned it. Source: Chrome Web Store reviews via Koi Security
  • Google removes the dead AgreeTo Chrome extension from Chrome Web Store. Microsoft's Office Store still lists the Outlook add-in. The Vercel deployment is deleted, making the subdomain outlook-one.vercel.app claimable by anyone. Source: Koi Security
  • Attacker claims the orphaned Vercel subdomain outlook-one.vercel.app and deploys a four-page phishing kit: fake Microsoft login, password collection, Telegram-based exfiltration, redirect to real login.microsoftonline.com. Microsoft's infrastructure now serves a phishing page inside Outlook's trusted sidebar. Estimated date — exact takeover timing unknown. Source: Koi Security
  • Koi Security publishes discovery of the first known malicious Outlook add-in in the wild. Over 4,000 stolen credential sets recovered from attacker's poorly-secured Telegram exfiltration channel. Same attacker operates 12+ phishing kits targeting Canadian banks, ISPs, and webmail. Campaign is ACTIVE — new victims compromised hourly. Reported to Microsoft, Vercel, and Telegram. Source: Koi Security / Malwarebytes
  • As of 2026-05-29, this AgreeToSteal incident is resolved: Microsoft removed the hijacked AgreeTo Outlook add-in from its store on Feb 11, 2026 (same day Koi Security reported it) and took steps to protect impacted users, with no re-emergence since. No CVE/KEV applies; the financially-motivated operator still runs ~12 other phishing kits and Microsoft's post-approval URL-validation gap persists.

Sources cited for Rogue AgreeTo Outlook Add-In

Detection coverage for TL-2026-0077

As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0077 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats