Executive Summary
In Q4 2025, approximately 10% of compromised Microsoft 365 accounts were found to have malicious mailbox rules created within seconds of initial access. Attackers leverage these native features to achieve stealthy persistence that survives password resets, as forwarding and suppression rules remain active until manually removed. This technique is a cornerstone of modern Business Email Compromise (BEC) and mass spam operations.
The attack chain typically begins with credential phishing or session token theft to bypass MFA. Once inside, adversaries deploy rules with nonsensical names like '.' or '...' to hide their activity. These rules are used to move security notifications or vendor communications to obscure folders like 'RSS Subscriptions' or 'Archive,' allowing attackers to manipulate email threads and conduct fraudulent transactions without the user's knowledge.
This trend represents a shift toward cloud-native post-exploitation where attackers use legitimate platform functionality rather than malware to operate. Organizations, particularly in the education and commercial sectors, must prioritize the monitoring of rule creation events and restrict external auto-forwarding to mitigate these risks.
