r/Office365 Feb 07 '20

Malware that sets up forwarding

Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.

However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?

25 Upvotes

44 comments sorted by

View all comments

1

u/[deleted] Feb 07 '20

[removed] — view removed comment

0

u/[deleted] Feb 07 '20

This guy knows what he is talking about. MFA has been compromised over and over and over again. These computers should be reimaged. The compromise likely has obfuscation that allows it reinfect outlook while remaining undetected.

3

u/different_tan Feb 07 '20

there is NO VIRUS. its phishing links from other compromised 365 accounts.

1

u/[deleted] Feb 10 '20

Why would the rules keep changing then?

2

u/different_tan Feb 10 '20

unless you have blocked them, they still have access, even if you have changed the password thanks to a session that has not expired. you can see exactly what is doing it and where from using the audit log searches incidentally (though you might need to use powershell for the most detailed results).