Rogue external MFA providers can steal passwords during logins

Rogue external MFA providers can steal passwords during logins
Varonis Threat Labs developed TrustSink, an attack that abuses Microsoft Entra’s external MFA provider model to steal passwords during a normal sign-in flow. The technique requires a previously compromised highly privileged account and can persist until the rogue provider is removed, even if victims reset their passwords. #TrustSink #MicrosoftEntra #VaronisThreatLabs #MFA

Keypoints

  • TrustSink lets an attacker register a rogue external MFA provider.
  • The attack injects a fake Microsoft password prompt during login.
  • Victims enter passwords into a page controlled by the attacker.
  • The rogue provider returns a valid signed token to complete sign-in.
  • Removing the malicious provider is required before resetting passwords.

Read More: https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/