TrustSink: How a Rogue External MFA Provider Steals Passwords
Meet TrustSink, a technique that turns a rogue external MFA provider into a persistent credential trap. See how it works, why password resets may not remove the risk, and how defenders can detect rogue providers.
Varonis Threat Labs identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow.
While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow. The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error.
In our test tenant, every sign-in completed normally while our server received passwords with timestamps and source IP addresses. Resetting a captured password did not remove the rogue...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE