Varonis Threat Labs developed TrustSink, an attack that abuses Microsoft Entra’s external MFA provider model to steal passwords during a normal sign-in flow. The technique requires a previously compromised highly privileged account and can persist until the rogue provider is removed, even if victims reset their passwords. #TrustSink #MicrosoftEntra #VaronisThreatLabs #MFA
Keypoints
- TrustSink lets an attacker register a rogue external MFA provider.
- The attack injects a fake Microsoft password prompt during login.
- Victims enter passwords into a page controlled by the attacker.
- The rogue provider returns a valid signed token to complete sign-in.
- Removing the malicious provider is required before resetting passwords.