Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Rogue external MFA providers can steal passwords during sign-ins

Security researchers at Varonis Threat Labs have developed an attack called TrustSink that can let hackers with privileged access steal passwords during legitimate Microsoft Entra sign-ins.

The attack abuses Entra’s support for external multifactor authentication providers. An attacker who has already compromised a highly privileged Entra account can register a rogue External Authentication Method (EAM) and place it in the tenant’s Authentication Methods Policy.

When a user completes the initial sign-in, Entra redirects the browser to the external provider for the MFA step. TrustSink displays a convincing copy of Microsoft’s password prompt, capturing a password in plaintext before returning a valid signed token that tells Entra the MFA requirement was completed. The user can then continue to the intended application without seeing an error.

Varonis says the imitation page uses Microsoft’s fonts, layout, and button design and appears after the user has entered a password on Microsoft’s legitimate domain. The technique is not an initial-access attack because it requires control of a highly privileged account.

Changing a captured password does not remove the rogue provider, which can capture the replacement during a later sign-in. Varonis recommends removing suspicious providers, associated applications, keys, and redirect URIs before resetting affected passwords. It also advises monitoring policy changes, limiting standing administrator privileges, and using phishing-resistant methods such as FIDO2 or Windows Hello for Business.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.