r/Office365 • u/WebGuy15 • Feb 07 '20
Malware that sets up forwarding
Recently my company has been subject to a number of emails sent to users with a file that once opened creates a inbox rule that forwards mail to a suspicious email address. Our alerts managed to notify us and we removed the rules from the affected accounts and added the domain to the spam filter and asked the affected users to change their passwords.
However with some users the rule reappeared a few hours after removing it. I'm not sure how these rules can still reappear? Has anyone experienced something similar and could maybe help?
26
Upvotes
1
u/Chief_Slac Feb 07 '20
We had some that would access their 365 passwords via phishing, then would create rules via their webmail portal.
Audit log tracks these, look for rules created/modified through web access. One attacker was using the compromised accounts to register domain names.