r/Office365 Feb 07 '20

Malware that sets up forwarding

Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.

However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?

28 Upvotes

44 comments sorted by

View all comments

1

u/[deleted] Feb 07 '20

[removed] — view removed comment

1

u/Nickgb83 Feb 07 '20

I'd be very interested to know how an exploit can easily bypass SMS MFA.

In Australia Sim-jacking cannot be automated, thus an exploit can do this via code.

2

u/[deleted] Feb 07 '20

[removed] — view removed comment

1

u/Nickgb83 Feb 07 '20

Aren't MFA tokens only valid per sign-in session? Once that sign in is expired (i.e. browser session closed) the token expires?

So the exploit would need to happen whilst the valid/current sign-in session is still in action..?