Vulnerabilities

TrustSink Attack Steals Passwords via Rogue External MFA Providers in Microsoft Entra

September 23, 2026 12:04 · 6 min read
TrustSink Attack Steals Passwords via Rogue External MFA Providers in Microsoft Entra

Understanding the TrustSink Attack Mechanism

Security researchers from Varonis Threat Labs have identified a novel attack technique named TrustSink that enables threat actors to steal user passwords during legitimate multi-factor authentication (MFA) flows. The attack requires the adversary to first compromise a highly privileged account within Microsoft Entra, such as a Global Administrator or Authentication Policy Administrator role, before they can register a rogue external MFA provider.

Microsoft Entra supports external MFA providers, allowing organizations to integrate third-party authentication services to fulfill MFA requirements. During a standard login, after the user enters their password (first factor), Entra redirects them to the configured external provider for the second authentication step. If the provider returns a valid signed token confirming MFA completion, Entra grants access.

How TrustSink Exploits Trust in External MFA Providers

In the TrustSink attack, the malicious actor registers a fraudulent external authentication method (EAM) that appears legitimate to Entra. However, instead of requesting a genuine second factor like a push notification or code, the rogue provider presents a convincing replica of Microsoft’s password prompt. This fake page mimics the legitimate login.microsoftonline.com interface in fonts, layout, and button design, appearing immediately after the user submits their real password on Microsoft’s domain.

Believing the prompt is part of the expected MFA process, the user re-enters their password, which is then captured in plaintext by the attacker-controlled server. The rogue provider subsequently generates and returns a valid signed token to Entra, falsely indicating that the second factor was satisfied. As a result, the login proceeds normally from the user’s perspective, with no error messages or signs of compromise.

Persistence and Impact of the Rogue Provider

Varonis researchers confirmed in their test environment that every sign-in appeared successful while their server collected passwords along with timestamps and source IP addresses. Critically, resetting a compromised password does not eliminate the threat, as the rogue provider remains registered in the tenant’s Authentication Methods Policy and continues to capture replacement passwords during subsequent logins.

"Resetting a captured password did not remove the rogue provider. It remained in the authentication flow and captured the replacement password at the user's next sign-in," explained Varonis researchers, highlighting the attack’s persistence.

Prerequisites and Attack Requirements

TrustSink is not an initial-access vector; it is a post-compromise technique that depends on the attacker already holding elevated privileges in Entra ID. Registering a malicious external MFA provider requires modifying the Authentication Methods Policy, creating an application, establishing a service principal, and granting consent — actions restricted to Global Administrator or Authentication Policy Administrator roles.

The researchers noted that TrustSink builds upon earlier work by security researcher Dirk-Jan Mollema, who demonstrated at x33fcon 2025 how a rogue external MFA provider could bypass MFA by returning a signed JWT without performing actual authentication. TrustSink adapts this concept for credential harvesting rather than mere bypass.

Mitigation and Defensive Recommendations

To defend against TrustSink, Varonis advises organizations to immediately remove any suspicious external MFA providers and their associated components — including applications, service principals, keys, and redirect URIs — before initiating password resets for affected users. Failure to do so risks re-capturing newly set credentials.

Additional preventive measures include monitoring for unauthorized changes to the Authentication Methods Policy, enforcing least-privilege access by limiting standing Global Administrator and Authentication Policy Administrator roles, and adopting phishing-resistant authentication methods such as FIDO2 security keys or Windows Hello for Business, which are not vulnerable to this form of credential theft.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free