TrustSink: rogue external MFA provider steals passwords in Microsoft Entra logins
Varonis Threat Labs detailed TrustSink, an attack where an adversary with privileged access registers a rogue external MFA provider in Microsoft Entra that shows a copy of Microsoft's password prompt, captures the password in plaintext, then returns a valid signed token so the login completes normally.
- Attack requires an already compromised highly privileged Entra account
- Rogue provider mimics Microsoft's password page and captures the password in plaintext
- The malicious provider survives password resets and recaptures the new password
- Varonis advises removing suspicious EAM providers before rotating credentials and using FIDO2
Read next
Security