Weaponized Microsoft Outlook Add-ins Exploit User Credentials

Weaponized Microsoft Outlook Add-ins Exploit User Credentials

First seen 12 Feb 2026, 12:40 UTC CybersecuritynewsThehackernewsBleepingcomputerGbhackersBlog.Malwarebytes+3 79% similarity 39.7

Article Content

Browse articles
ThreatCluster

A dormant Microsoft Outlook add-in has been weaponized, leading to the theft of thousands of login credentials and credit card numbers. This incident marks the first known malicious Office add-in discovered in the wild, revealing a critical flaw in Microsoft's distribution of third-party tools. Additionally, a new attack technique called 'Exfil Out&Look' has been identified, allowing threat actors to exfiltrate sensitive email data without leaving forensic traces.

ThreatCluster AI

Timeline

2022-01-01
Developer published the dormant Outlook add-in
2026-01-29
Exfil Out&Look attack technique reported
2026-02-12
Microsoft Outlook add-in weaponization reported

Community

Browse all →