Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Attackers Intercept AI Prompts via Fake Jev AI Stores
September 28, 2026
NVIDIA Unveils Open Safety Platform for Autonomous AI Agents With 100 Partners
September 28, 2026
TrustSink Attack Steals Microsoft Entra Passwords via Rogue MFA Provider
September 28, 2026
Home/Threats/TrustSink Attack Steals Microsoft Entra Passwords via Rogue MFA Provider
Threats

TrustSink Attack Steals Microsoft Entra Passwords via Rogue MFA Provider

Key Takeaways TrustSink is a novel identity attack that hijacks the Microsoft Entra MFA process to steal user passwords. The attack leverages a rogue External Authentication Method (EAM) that...

Emy Elsamnoudy
Emy Elsamnoudy
September 28, 2026 4 Min Read
3 0

Key Takeaways

  • TrustSink is a novel identity attack that hijacks the Microsoft Entra MFA process to steal user passwords.
  • The attack leverages a rogue External Authentication Method (EAM) that presents a convincing, in-line password prompt to users during a legitimate login.
  • Successful execution requires initial compromise of a highly privileged Entra account (e.g., Global Administrator or Authentication Policy Administrator).
  • The technique serves as a post-compromise persistence mechanism, allowing attackers to continuously capture new passwords even after a password reset.
  • Organizations should actively monitor Entra authentication policies, application registrations, and sign-in logs for suspicious activities.

TrustSink: A Sophisticated Password Theft Mechanism

A new identity attack, dubbed TrustSink, has been unveiled, demonstrating a highly deceptive method for stealing Microsoft Entra passwords. Unlike traditional phishing attempts that redirect users to obviously fake websites, TrustSink seamlessly integrates a fraudulent password prompt directly within a legitimate Microsoft Entra sign-in flow, exploiting the trust inherent in multi-factor authentication (MFA) processes.

Table Of Content

  • Key Takeaways
  • TrustSink: A Sophisticated Password Theft Mechanism
  • How the TrustSink Attack Operates
  • What You Should Do

Researchers at Varonis discovered and demonstrated this technique within a controlled Microsoft Entra tenant. Their findings, detailed in a report, indicate that TrustSink is designed as a persistence mechanism following an initial compromise, rather than an initial access vector. This means an attacker would first need to gain control of a privileged Entra account, such as a Global Administrator or an Authentication Policy Administrator.

The insidious nature of TrustSink lies in its ability to allow victims to complete their MFA and access their intended application without encountering any apparent errors. This seamless experience makes the attack exceptionally difficult to detect for end-users. Furthermore, a simple password reset may not fully mitigate the threat, as the rogue authentication provider can remain active and subsequently capture the new credentials during the next login attempt.

How the TrustSink Attack Operates

The TrustSink attack exploits Microsoft Entra’s External Authentication Method (EAM) feature, which allows Entra to integrate with third-party authentication providers during the MFA sequence. The malicious provider orchestrates a sophisticated deception, presenting two distinct outcomes for the same event:

  • To Microsoft Entra: The rogue provider sends a cryptographically signed response, falsely confirming that the MFA check, such as a hardware-key verification, has successfully completed.
  • To the User: Concurrently, the user is presented with a pixel-perfect replica of a Microsoft password page. This prompt appears at a seemingly normal stage of the login process, after the user has already entered their initial password and initiated MFA.

Upon the victim entering their password into this deceptive prompt, the attacker-controlled provider silently records the credentials. After capturing the information, the user is seamlessly redirected back to their intended application, completing the login process as if nothing untoward occurred. This method ensures the attack is unobtrusive, making it challenging for users to identify the compromise.

The malicious provider establishes its presence by publishing a discovery document and a public signing key, which Microsoft Entra uses to validate its responses. It then submits a signed token containing claims that falsely indicate a successful hardware-key check, allowing the authentication process to proceed without suspicion. This sophisticated abuse of trust relationships within identity applications highlights a growing trend where attackers target the authentication infrastructure itself, rather than relying on less convincing phishing lures or browser exploits. Unlike OAuth app persistence techniques that create lasting access paths, TrustSink focuses on capturing fresh passwords during live sign-ins.

What You Should Do

  • Audit External Authentication Methods: Regularly review all externalAuthenticationMethodConfiguration entries within your Microsoft Entra environment. Investigate any additions or modifications that fall outside of approved and known deployments.
  • Correlate Audit Events: Scrutinize audit logs for a rapid succession of events, including newly created applications, service principals, consent grants, group assignments, or unusual redirect URIs, especially when these actions occur in close proximity (within seconds).
  • Examine Sign-in Logs for Anomalies: Check sign-in logs for unfamiliar issuer URLs associated with external authentication methods. Specifically, look for instances where hardware-key-related claims are reported by an unknown issuer, as this can be a strong indicator of a TrustSink attack.
  • Incident Response Protocol: If TrustSink is suspected, immediately disable and remove the suspicious external authentication method and its associated group assignments. Prioritize resetting passwords for all users who logged in through the compromised provider. Subsequently, remove the related app registration, service principal, signing keys, consent grants, and redirect URIs. Conduct a thorough investigation of affected user activity post-compromise.
  • Strengthen Authentication Methods: Encourage and enforce the use of phishing-resistant authentication methods such as FIDO2 security keys or Windows Hello for Business. This makes unexpected password prompts during MFA much easier for users to identify as malicious. The broader push for Entra passkey rollout underscores the critical need to reduce reliance on reusable passwords, particularly for administrators with elevated privileges.
  • Implement Least Privilege: Strictly limit standing Global Administrator and Authentication Policy Administrator privileges. Employ a principle of least privilege and conduct frequent reviews of these highly sensitive accounts to minimize the attack surface and prevent a single compromised account from becoming a persistent credential harvesting point.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

OpenAI Agent Swarm Bypass Exposes 80,000 Attack Payloads

Next Post

NVIDIA Unveils Open Safety Platform for Autonomous AI Agents With 100 Partners

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Kiteworks Zero-Day Vulnerability Prompts Server Shutdown Warning
September 28, 2026
CISA Warns of Critical Citrix NetScaler RCE 0-Day Vulnerabilities Under Attack
September 28, 2026
PHP Patches Critical Credential Exposure Vulnerability
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us