Microsoft 365 Malicious Mailbox Rule Abuse
Score: 8/10

Microsoft 365 Malicious Mailbox Rule Abuse

Threat actors are increasingly abusing native Microsoft 365 mailbox rules to maintain persistence, suppress security alerts, and automate data exfiltration following account compromise.

Executive Summary

In Q4 2025, approximately 10% of compromised Microsoft 365 accounts were found to have malicious mailbox rules created within seconds of initial access. Attackers leverage these native features to achieve stealthy persistence that survives password resets, as forwarding and suppression rules remain active until manually removed. This technique is a cornerstone of modern Business Email Compromise (BEC) and mass spam operations.

The attack chain typically begins with credential phishing or session token theft to bypass MFA. Once inside, adversaries deploy rules with nonsensical names like '.' or '...' to hide their activity. These rules are used to move security notifications or vendor communications to obscure folders like 'RSS Subscriptions' or 'Archive,' allowing attackers to manipulate email threads and conduct fraudulent transactions without the user's knowledge.

This trend represents a shift toward cloud-native post-exploitation where attackers use legitimate platform functionality rather than malware to operate. Organizations, particularly in the education and commercial sectors, must prioritize the monitoring of rule creation events and restrict external auto-forwarding to mitigate these risks.

Key Details

Threat Name

O365 Malicious Mailbox Rule Abuse

Affects

—

Adversary

—

Malware/Tools

ATOLS

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance6
Enterprise Relevance10
Clarity & Structure10
Technical Depth7

Sources