TrustSink Attack Steals Microsoft Entra Passwords via Rogue MFA Provider
Key Takeaways TrustSink is a novel identity attack that hijacks the Microsoft Entra MFA process to steal user passwords. The attack leverages a rogue External Authentication Method (EAM) that...
Key Takeaways
- TrustSink is a novel identity attack that hijacks the Microsoft Entra MFA process to steal user passwords.
- The attack leverages a rogue External Authentication Method (EAM) that presents a convincing, in-line password prompt to users during a legitimate login.
- Successful execution requires initial compromise of a highly privileged Entra account (e.g., Global Administrator or Authentication Policy Administrator).
- The technique serves as a post-compromise persistence mechanism, allowing attackers to continuously capture new passwords even after a password reset.
- Organizations should actively monitor Entra authentication policies, application registrations, and sign-in logs for suspicious activities.
TrustSink: A Sophisticated Password Theft Mechanism
A new identity attack, dubbed TrustSink, has been unveiled, demonstrating a highly deceptive method for stealing Microsoft Entra passwords. Unlike traditional phishing attempts that redirect users to obviously fake websites, TrustSink seamlessly integrates a fraudulent password prompt directly within a legitimate Microsoft Entra sign-in flow, exploiting the trust inherent in multi-factor authentication (MFA) processes.
Table Of Content
Researchers at Varonis discovered and demonstrated this technique within a controlled Microsoft Entra tenant. Their findings, detailed in a report, indicate that TrustSink is designed as a persistence mechanism following an initial compromise, rather than an initial access vector. This means an attacker would first need to gain control of a privileged Entra account, such as a Global Administrator or an Authentication Policy Administrator.
The insidious nature of TrustSink lies in its ability to allow victims to complete their MFA and access their intended application without encountering any apparent errors. This seamless experience makes the attack exceptionally difficult to detect for end-users. Furthermore, a simple password reset may not fully mitigate the threat, as the rogue authentication provider can remain active and subsequently capture the new credentials during the next login attempt.
How the TrustSink Attack Operates
The TrustSink attack exploits Microsoft Entra’s External Authentication Method (EAM) feature, which allows Entra to integrate with third-party authentication providers during the MFA sequence. The malicious provider orchestrates a sophisticated deception, presenting two distinct outcomes for the same event:
- To Microsoft Entra: The rogue provider sends a cryptographically signed response, falsely confirming that the MFA check, such as a hardware-key verification, has successfully completed.
- To the User: Concurrently, the user is presented with a pixel-perfect replica of a Microsoft password page. This prompt appears at a seemingly normal stage of the login process, after the user has already entered their initial password and initiated MFA.
Upon the victim entering their password into this deceptive prompt, the attacker-controlled provider silently records the credentials. After capturing the information, the user is seamlessly redirected back to their intended application, completing the login process as if nothing untoward occurred. This method ensures the attack is unobtrusive, making it challenging for users to identify the compromise.
The malicious provider establishes its presence by publishing a discovery document and a public signing key, which Microsoft Entra uses to validate its responses. It then submits a signed token containing claims that falsely indicate a successful hardware-key check, allowing the authentication process to proceed without suspicion. This sophisticated abuse of trust relationships within identity applications highlights a growing trend where attackers target the authentication infrastructure itself, rather than relying on less convincing phishing lures or browser exploits. Unlike OAuth app persistence techniques that create lasting access paths, TrustSink focuses on capturing fresh passwords during live sign-ins.
What You Should Do
- Audit External Authentication Methods: Regularly review all
externalAuthenticationMethodConfigurationentries within your Microsoft Entra environment. Investigate any additions or modifications that fall outside of approved and known deployments. - Correlate Audit Events: Scrutinize audit logs for a rapid succession of events, including newly created applications, service principals, consent grants, group assignments, or unusual redirect URIs, especially when these actions occur in close proximity (within seconds).
- Examine Sign-in Logs for Anomalies: Check sign-in logs for unfamiliar issuer URLs associated with external authentication methods. Specifically, look for instances where hardware-key-related claims are reported by an unknown issuer, as this can be a strong indicator of a TrustSink attack.
- Incident Response Protocol: If TrustSink is suspected, immediately disable and remove the suspicious external authentication method and its associated group assignments. Prioritize resetting passwords for all users who logged in through the compromised provider. Subsequently, remove the related app registration, service principal, signing keys, consent grants, and redirect URIs. Conduct a thorough investigation of affected user activity post-compromise.
- Strengthen Authentication Methods: Encourage and enforce the use of phishing-resistant authentication methods such as FIDO2 security keys or Windows Hello for Business. This makes unexpected password prompts during MFA much easier for users to identify as malicious. The broader push for Entra passkey rollout underscores the critical need to reduce reliance on reusable passwords, particularly for administrators with elevated privileges.
- Implement Least Privilege: Strictly limit standing Global Administrator and Authentication Policy Administrator privileges. Employ a principle of least privilege and conduct frequent reviews of these highly sensitive accounts to minimize the attack surface and prevent a single compromised account from becoming a persistent credential harvesting point.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.