TrustSink Attack Can Steal Passwords During Microsoft Entra MFA Logins


TrustSink microsoft entra
Image credit: Microsoft

TrustSink attack abuses Microsoft Entra external MFA providers to steal passwords by inserting a rogue authentication provider into legitimate Microsoft Entra sign-ins.

Varonis Threat Labs demonstrated the post-compromise technique, which can capture user passwords even when victims believe they are completing a normal MFA process.

The attack requires hackers to already control a highly privileged account, such as a Global Administrator or Authentication Policy Administrator. This means TrustSink cannot provide initial access to an organization.

TrustSink creates a fake Microsoft password prompt

Microsoft Entra supports External Authentication Methods, allowing organizations to use third-party providers for MFA.

TrustSink abuses this feature by registering a malicious external MFA provider. When users reach the second authentication step, the provider redirects them to a convincing copy of Microsoft’s password prompt.

After the user enters a password, the malicious provider captures it and returns a valid signed token stating that MFA succeeded. The Microsoft Entra sign-in then completes normally, giving users little indication that anything went wrong.

Password resets alone will not remove the attack

The rogue provider remains registered in the tenant’s Authentication Methods Policy. As a result, resetting a compromised password does not stop TrustSink.

A user who signs in again can reach the same fake password prompt, allowing attackers to capture the replacement password.

Varonis says administrators should remove the malicious external MFA provider before resetting affected credentials.

Organizations should also monitor changes to Authentication Methods Policy and restrict standing Global Administrator and Authentication Policy Administrator privileges.

Using phishing-resistant authentication methods such as FIDO2 security keys or Windows Hello for Business can further reduce exposure.

In other security news, a new BigDiskBuster zero-day can block Microsoft Defender updates, while ClosedQuorum malware uses multiple AI models to guide attacks.

Microsoft has also again urged Entra ID users to move from SMS authentication to passkeys.

Via BleepingComputer

More about the topics: microsoft entra, Phishing

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages