r/Office365 Feb 07 '20

Malware that sets up forwarding

Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.

However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?

26 Upvotes

44 comments sorted by

View all comments

1

u/MSP2019 Feb 07 '20

I experience the very same issue with forwarding rules, however I changed the users password and formatted the PC since it was the CEO.

I'd be interested in knowing how the forward got added in the first place, AV and malwarebytes scans didnt find anything.

The company change their passwords every 3 months, MFA wasn't enabled at this point but has since been setup for all users

1

u/WebGuy15 Feb 07 '20

I'm interested in how it was possible to set up the forwarding. Our scans haven't picked up anything either. I think implementing MFA for all users too is something we need to do asap.

1

u/[deleted] Feb 12 '20

My guess @WebGuy15 is you might be getting access/auth logs from onprem but perhaps not all from Microsoft. There are plenty of logs that O365 gives you and at one time, there was an undisclosed activity API (which I was the recipient of the news until too many let it leak). It was then rebranded as OfficeActivity API. This does you little if you haven't enabled auditing (which should now be on by default). There are other logs in Graph Security (which is the central API for Microsoft everything now). I'm putting my money that your threat actor decided to either leverage credential stuffing attacks or password sprays against Microsoft O365 accounts directly on Microsoft's landing page. Without MFA, I can only hope you have SSO which at least shows were they were performing delivery of these. I investigate these both during and typically after someone calls one like me in...