Security researchers at Varonis Threat Labs have developed an attack called TrustSink that can let hackers with privileged access steal passwords during legitimate Microsoft Entra sign-ins.
The attack abuses Entra’s support for external multifactor authentication providers. An attacker who has already compromised a highly privileged Entra account can register a rogue External Authentication Method (EAM) and place it in the tenant’s Authentication Methods Policy.
When a user completes the initial sign-in, Entra redirects the browser to the external provider for the MFA step. TrustSink displays a convincing copy of Microsoft’s password prompt, capturing a password in plaintext before returning a valid signed token that tells Entra the MFA requirement was completed. The user can then continue to the intended application without seeing an error.
Varonis says the imitation page uses Microsoft’s fonts, layout, and button design and appears after the user has entered a password on Microsoft’s legitimate domain. The technique is not an initial-access attack because it requires control of a highly privileged account.
Changing a captured password does not remove the rogue provider, which can capture the replacement during a later sign-in. Varonis recommends removing suspicious providers, associated applications, keys, and redirect URIs before resetting affected passwords. It also advises monitoring policy changes, limiting standing administrator privileges, and using phishing-resistant methods such as FIDO2 or Windows Hello for Business.
Comments
0No comments yet. Be the first to comment.