Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Abuse of Microsoft 365 mailbox rules provides stealthy post-compromise persistence.
- Rules can forward emails, delete security alerts, or hide malicious messages.
- Researchers recommend auditing and monitoring mailbox rule changes.
"Researchers warn that attackers are exploiting Microsoft 365 mailbox rules to maintain persistence, hide malicious activity, and exfiltrate data after compromising accounts. The technique allows stealthy post-compromise operations."
no comments yet.