TrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins
Varonis disclosed TrustSink, a post-compromise Entra technique that steals passwords via a rogue MFA provider.
Varonis researchers demonstrated TrustSink in a test Microsoft Entra tenant as a post-compromise persistence technique, not an initial-access method. After a privileged account such as Global Administrator or Authentication Policy Administrator is compromised, the attacker registers a rogue External Authentication Method. Entra receives a signed MFA success while the user is shown a lookalike Microsoft password page that records the credential and then returns them to the app. If the provider stays in place, a later password reset can be captured again; Varonis advises auditing external authentication methods and removing the rogue provider before resetting passwords.