Gbhackers
Weaponized Microsoft Outlook Add-ins Exploit User Credentials
First seen 12 Feb 2026, 12:40 UTC
•



+3
•79% similarity
•39.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A dormant Microsoft Outlook add-in has been weaponized, leading to the theft of thousands of login credentials and credit card numbers. This incident marks the first known malicious Office add-in discovered in the wild, revealing a critical flaw in Microsoft's distribution of third-party tools. Additionally, a new attack technique called 'Exfil Out&Look' has been identified, allowing threat actors to exfiltrate sensitive email data without leaving forensic traces.
ThreatCluster AI
Timeline
2022-01-01
Developer published the dormant Outlook add-in
2026-01-29
Exfil Out&Look attack technique reported
2026-02-12
Microsoft Outlook add-in weaponization reported