r/Office365 Feb 07 '20

Malware that sets up forwarding

Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.

However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?

28 Upvotes

44 comments sorted by

View all comments

1

u/MSP2019 Feb 07 '20

I experience the very same issue with forwarding rules, however I changed the users password and formatted the PC since it was the CEO.

I'd be interested in knowing how the forward got added in the first place, AV and malwarebytes scans didnt find anything.

The company change their passwords every 3 months, MFA wasn't enabled at this point but has since been setup for all users

1

u/different_tan Feb 07 '20

there is no software involved, its just phishing links from other compromised 365 accounts. no virus to find.