# Rogue AgreeTo Outlook Add-In: Abandoned Extension Hijacked Into Supply Chain Phishing Kit — 4,000+ Credentials and Payment Data Stolen

> AgreeTo, a legitimate Microsoft Outlook add-in for meeting scheduling published in December 2022, was abandoned by its developer and subsequently hijacked by a cybercriminal who claimed the orphaned Vercel subdomain (outlook-one.vercel.app) to deploy a phishing kit inside Outlook's trusted sidebar. The attack exploited a structural flaw in Microsoft's Office Add-in architecture: add-ins are remote URLs loaded in iframes, and Microsoft reviews the manifest at submission but never re-validates what the URL serves afterward. The attacker harvested 4,000+ Microsoft account credentials, credit card numbers, CVVs, PINs, and banking security answers, exfiltrating data via Telegram Bot API. The same attacker operates at least 12 distinct phishing kits targeting Canadian ISPs, banks, and webmail providers — a professional multi-brand phishing operation. The AgreeTo add-in retained ReadWriteItem permissions (read and modify user emails) from its original legitimate review, meaning the attacker could have silently read inboxes, exfiltrated messages, or sent phishing from victims' accounts. Discovered by Koi Security, reported by Malwarebytes. Infrastructure is LIVE as of publication.

- **Published:** 2026-02-12T15:33:00Z
- **Last reviewed:** 2026-02-12T15:33:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0077
- **ID:** TL-2026-0077
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** RESOLVED
- **Detections:** 12 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

THE FIRST KNOWN MALICIOUS MICROSOFT OUTLOOK ADD-IN DETECTED IN THE WILD

This attack represents a novel supply chain vector: the weaponization of abandoned Office add-ins through URL takeover. It exploits a fundamental architectural flaw in how Microsoft distributes and maintains trust for Office add-ins.

ATTACK CHAIN:

1. LEGITIMATE ORIGIN (Dec 2022): A developer built AgreeTo, an open-source meeting scheduling tool with a Chrome extension (1,000 users, 4.71-star rating, 21 reviews) and an Outlook add-in. Published to Microsoft's Office Add-in Store with ReadWriteItem permissions (read and modify user emails). Microsoft reviewed the XML manifest, signed it, and listed it. The manifest pointed to outlook-one.vercel.app.

2. ABANDONMENT (May 2023): Developer stopped maintaining AgreeTo. Last Chrome extension update: May 2023. Developer's domain (agreeto.app) expired. By July 2024, users were leaving reviews: 'Did this app die? No longer works.' Google removed the dead Chrome extension in February 2025. But the Outlook add-in stayed listed in Microsoft's Office Store.

3. URL TAKEOVER: The developer's Vercel deployment was deleted. The subdomain outlook-one.vercel.app became claimable. An attacker registered the subdomain and deployed a four-page phishing kit: (1) fake Microsoft sign-in page, (2) password collection page, (3) Telegram-based exfiltration script, (4) redirect to real login.microsoftonline.com.

4. PHISHING DELIVERY: When victims opened AgreeTo in Outlook, they saw what appeared to be a normal Microsoft sign-in inside Outlook's trusted sidebar. Credentials were captured via a JavaScript fetch() call to the attacker's Telegram bot (with IP data), then victims were redirected to the real Microsoft login. Seamless — victims assumed they needed to sign in again.

ARCHITECTURAL FLAW:
Office add-ins are NOT installed code. They are URLs. A developer submits an XML manifest to Microsoft that says 'load this URL in an iframe inside Outlook.' Microsoft reviews the manifest once at submission but NEVER checks what the URL serves again. The actual content — UI, logic, everything — is fetched live from the developer's server every time the add-in opens. If someone else takes control of that URL, they control what every user sees — inside Outlook's trusted sidebar, with whatever permissions were originally granted.

WHY EXISTING SECURITY TOOLS MISS THIS:
- Email security gateways: phishing page doesn't arrive via email
- Endpoint protection: JavaScript running inside a legitimate Microsoft process (Outlook)
- URL filtering: hosted on vercel.app, which serves millions of legitimate applications
- Static analysis: no installed binary to scan — content is fetched dynamically

SCALE AND OPERATOR PROFILE:
- 4,000+ stolen credential sets recovered by Koi Security
- Credit card numbers, CVVs, PINs, and banking security answers also stolen
- Interac e-Transfer payment interception (Canadian banking)
- At least 12 distinct phishing kits operated by same attacker, each impersonating different brands (Canadian ISPs, banks, webmail)
- Professional multi-brand phishing operation — AgreeTo was one distribution channel
- Campaign is STILL ACTIVE — new victims being compromised by the hour
- Attacker's exfiltration infrastructure was poorly secured (Koi accessed Telegram channel)
- Attacker was actively testing stolen credentials as of publication date

UNEXPLOITED POTENTIAL (ReadWriteItem):
The AgreeTo manifest declared ReadWriteItem permissions — the add-in can read AND modify the user's emails. The attacker only used it for a simple phishing page, but the permissions would have allowed: (1) silently reading the victim's entire inbox, (2) exfiltrating sensitive messages, (3) sending phishing emails FROM the victim's own account, (4) creating forwarding rules. The full potential of this attack vector was NOT exploited.

PRIOR RESEARCH:
MDSec flagged Office add-ins as an attack surface in 2019, demonstrating how they could be weaponized for persistent mailbox access. Their warning: 'Microsoft also allow developers to push these add-ins to a store, where users can install them. I'm sure you can see the potential problem there.' Seven years later, AgreeTo is exactly the scenario they predicted.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1608 Stage Capabilities
- T1199 Trusted Relationship
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1204 User Execution
- T1137 Office Application Startup
- T1056 Input Capture
- T1539 Steal Web Session Cookie
- T1555 Credentials from Password Stores
- T1114 Email Collection
- T1213 Data from Information Repositories
- T1553 Subvert Trust Controls
- T1036 Masquerading
- T1127 Trusted Developer Utilities Proxy Execution
- T1567 Exfiltration Over Web Service
- T1048 Exfiltration Over Alternative Protocol
- T1531 Account Access Removal
- T1596 Search Open Technical Databases
- T1594 Search Victim-Owned Websites
- T1059 Command and Scripting Interpreter
- T1176 Software Extensions
- T1552 Unsecured Credentials
- T1005 Data from Local System
- T1119 Automated Collection
- T1041 Exfiltration Over C2 Channel
- T1027 Obfuscated Files or Information
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1588 Obtain Capabilities

## Sources

- [Malwarebytes: Outlook Add-In Goes Rogue and Steals 4,000 Credentials and Payment Data](https://www.malwarebytes.com/blog/news/2026/02/outlook-add-in-goes-rogue-and-steals-4000-credentials-and-payment-data)
- [Koi Security: AgreeToSteal — The First Malicious Outlook Add-In Leads to 4,000 Stolen Credentials (Primary Research)](https://www.koi.ai/blog/agreetosteal-the-first-malicious-outlook-add-in-leads-to-4-000-stolen-credentials)
- [MDSec: Abusing Office Web Add-Ins for Fun and Limited Profit (2019 — Predicted This Attack)](https://www.mdsec.co.uk/2019/01/abusing-office-web-add-ins-for-fun-and-limited-profit/)
- [Microsoft: Office Add-Ins Platform Overview — Architecture Documentation](https://learn.microsoft.com/en-us/office/dev/add-ins/overview/office-add-ins)
- [Koi Security: Continuous Monitoring Platform for Office Add-Ins, Browser Extensions, and IDE Plugins](https://www.koi.security/get-a-demo)
- [Sperry Software: How to Uninstall Add-Ins from Microsoft Outlook (Remediation Guide)](https://www.sperrysoftware.com/Email-Tools/how-to-uninstall-add-ins-from-microsoft-outlook/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0077
