Microsoft Store Outlook Add-in Exploited in Widespread Heist of 4,000 Accounts

A malicious Outlook add-in called AgreeToSteal hijacked an abandoned calendar tool through Microsoft’s official Store, harvesting credentials from over 4,000 users alongside credit card numbers and banking PINs. Attackers exploited the developer’s December 2022 abandonment by claiming the expired Vercel subdomain, deploying a phishing kit that mimicked Microsoft’s login interface directly within Outlook’s sidebar. Microsoft’s Store never reviewed the actual code—only an XML manifest—allowing the compromised add-in to maintain a 4.71-star rating throughout the operation even as it exfiltrated data via basic Telegram bots, exposing critical gaps in platform security that persist in spite of 2019 warnings about architectural weaknesses in distribution channels.

Microsoft’s curated app marketplace has now become a phishing launchpad. Security researchers at Koi discovered AgreeToSteal, the first known malicious Outlook add-in distributed through the Microsoft Store that compromised over 4,000 user credentials. The attackers hijacked an abandoned calendar tool called AgreeTo, transforming a seemingly innocuous productivity extension into a credential-harvesting operation that also captured credit card numbers, CVVs, banking PINs, and security answers.

The attack mechanism was brilliantly simple. When AgreeTo’s developer abandoned the project after its December 2022 update, they left behind an expired Vercel subdomain powering the backend. An attacker claimed that domain and deployed a four-page phishing kit disguised as Microsoft’s login interface, appearing directly within Outlook’s sidebar. Users who trusted the Microsoft Store’s implicit endorsement entered credentials that were immediately captured via JavaScript and exfiltrated to a Telegram bot along with their IP addresses. After harvesting their data, victims were redirected to the legitimate login.microsoftonline.com, likely never suspecting the heist.

An expired domain became a phishing gateway, harvesting thousands of credentials through a trusted Microsoft Store add-in nobody thought to question.

Here’s the concerning part: Microsoft never reviewed the actual code. The store listing only requires an XML manifest detailing permissions and a URL. The hijacked add-in requested ReadWriteItem permissions, granting access to read and modify email content within Outlook. This created potential for far more extensive damage than simple credential theft. Techniques like Varonis’s Exfil Out&Look demonstrate how minimal-permission add-ins can stealthily siphon entire mailbox contents without triggering audit logs in certain scenarios.

The operation extended beyond Microsoft accounts. Researchers uncovered a professional phishing apparatus impersonating Australian ISPs, banks, and webmail providers across twelve different kits. The attackers particularly targeted Interac e-Transfer payment interceptions, suggesting financially motivated criminals comfortable exploiting multiple attack vectors. Their command-and-control infrastructure relied on basic Telegram bots rather than sophisticated servers, yet the poorly secured exfiltration channel they operated proved devastatingly effective.

This represents supply chain exploitation reaching Office environments. Similar hijacking attacks have plagued browser extensions, npm packages, and IDE plugins, but Microsoft’s add-in architecture distributes unreliable URLs without meaningful code review. The compromised listing maintained its 4.71-star rating throughout the attack, even as Google removed the corresponding Chrome extension in February 2025. Microsoft classified related security issues as low-severity with no immediate fix planned. The attack exploited the gap between developer abandonment and platform notification, a vulnerability in Microsoft’s distribution channels. Security experts had warned about this vulnerability since 2019, yet the architectural weakness persisted.

The broader implications should worry anyone handling sensitive communications through Outlook. We’ve collectively learned to scrutinise browser permissions and mobile app access, yet Office add-ins operate with similar privileges under far less scrutiny. When trusted marketplaces distribute malicious code through architectural oversights rather than sophisticated exploits, the weakest link becomes the vetting process itself. Your mailbox deserves the same security skepticism you’d apply anywhere else online.

Final Thoughts

The recent breach involving the Microsoft Store Outlook add-in underscores a significant vulnerability in even the most trusted app platforms. With 4,000 accounts compromised, this incident serves as a stark reminder for users to meticulously review their Outlook add-ins and remove any unfamiliar or unnecessary tools. The Virus Removal Brisbane team can assist in this crucial process by helping you secure your accounts and eliminate potential threats. Don’t wait until it’s too late—click on our contact us page to get in touch and ensure your digital safety today!