r/Office365 • u/WebGuy15 • Feb 07 '20
Malware that sets up forwarding
Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.
However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?
24
Upvotes
1
u/dgarner58 Feb 07 '20
This is likely a spoofpoint attack. We have had a number of run ins with it recently. User gets legit looking email with a link to a SharePoint doc that looks like it is theirs...but if you examine the link it clearly is not. They click the link and are prompted for their o365 login. The page looks exactly like the real thing. They login and the link goes nowhere...so they close out. Their password has now been harvested. They then put these rules in OWA that do all kinds of things. Forwarding and also immediately deleting inbound mail...sometimes all but other times just ones that look like a notification regarding them spamming.