{"id":50320,"date":"2023-01-26T20:00:00","date_gmt":"2023-01-26T20:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/saas-rootkit-exploits-hidden-rules-in-microsoft-365-"},"modified":"2023-01-26T20:00:00","modified_gmt":"2023-01-26T20:00:00","slug":"saas-rootkit-exploits-hidden-rules-in-microsoft-365","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/","title":{"rendered":"SaaS RootKit Exploits Hidden Rules in Microsoft 365"},"content":{"rendered":"<p>Microsoft is a primary target for threat actors, who scour Microsoft applications for weaknesses. Our security research team at Adaptive Shield recently discovered a new attack vector caused by a vulnerability within Microsoft&#8217;s OAuth application registration that allows attackers to leverage Exchange&#8217;s legacy API to create hidden forwarding rules in Microsoft 365 mailboxes.<\/p>\n<p>To understand this new attack vector, you must understand the key components therein. These include hidden forwarding rules and <a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/third-party-app-access-is-the-new-executable-file\">SaaS-to-SaaS app access<\/a>, all of which amount to a malicious SaaS rootkit that can infiltrate users&#8217; accounts and control their mailboxes \u2014 without the users&#8217; knowledge.<\/p>\n<p>Learn more about the <a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/www.adaptive-shield.com\/use-cases\">top use cases<\/a> to secure your entire SaaS stack.<\/p>\n<h2 class=\"regular-text\">Hidden Forwarding Rules<\/h2>\n<p>Inbox rules are actions that occur based on preset conditions within a Microsoft mailbox. Users or admins can use forwarding rules to trigger protocols based on different attributes of the user&#8217;s inbox.<\/p>\n<p>Hidden forwarding rules (Figure 1) were first discovered by Compass Security&#8217;s <a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/blog.compass-security.com\/2018\/09\/hidden-inbox-rules-in-microsoft-exchange\/\">Damian Pflammater<\/a> in 2018. He covered the discovery and Microsoft\u2019s response in a blog post titled &#8220;<a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/blog.compass-security.com\/2018\/09\/hidden-inbox-rules-in-microsoft-exchange\/\">Hidden Inbox Rules in Microsoft Exchange<\/a>.&#8221; These rules are fully functional and can be seen on the back end. However, they are not visible common interfaces such as email clients, an admin dashboard, or an API (Figure 2).<\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" alt=\"Figure 1. Hidden forwarding rules are visible on the back end.\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\">\n<\/picture><figcaption>Figure 1. Hidden forwarding rules are visible on the back end.<\/figcaption><\/figure>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6d9f5562579fd971\/63d2f07ac4f1c1744a725828\/BinFig2.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6d9f5562579fd971\/63d2f07ac4f1c1744a725828\/BinFig2.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6d9f5562579fd971\/63d2f07ac4f1c1744a725828\/BinFig2.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6d9f5562579fd971\/63d2f07ac4f1c1744a725828\/BinFig2.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" alt=\"Figure 2. Forwarding rules don\u2019t appear in searches through common interfaces. \" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6d9f5562579fd971\/63d2f07ac4f1c1744a725828\/BinFig2.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\">\n<\/picture><figcaption>Figure 2. Forwarding rules don\u2019t appear in searches through common interfaces.<\/figcaption><\/figure>\n<h2 class=\"regular-text\">SaaS-to-SaaS Access Through OAuth 2.0<\/h2>\n<p>SaaS-to-SaaS app access, also referred to as third-party app access, describes the conditions under which one app can connect to another app and, in doing so, gain access and permission to different information and settings. The <a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/cyberattackers-compromise-microsoft-exchange-servers-malicious-oauth-apps\">OAuth<\/a> 2.0 mechanism simplifies the process of authentication and authorization between consumers and service providers through a seamless process that allows users to quickly verify their identities and grant permissions to the app. The app is then allowed to execute code and perform logic within its environment behind the scenes.<\/p>\n<p>In many instances, these apps are completely harmless and often serve as a valuable business tool. In other instances, these apps can act as malware, similar to an executable file.<\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt90c5f6e60f356a9d\/63d2f0a5ba840d40d879bb1a\/BinFig3.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt90c5f6e60f356a9d\/63d2f0a5ba840d40d879bb1a\/BinFig3.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt90c5f6e60f356a9d\/63d2f0a5ba840d40d879bb1a\/BinFig3.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt90c5f6e60f356a9d\/63d2f0a5ba840d40d879bb1a\/BinFig3.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" alt=\"Figure 3. Connecting third-party apps.\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt90c5f6e60f356a9d\/63d2f0a5ba840d40d879bb1a\/BinFig3.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\">\n<\/picture><figcaption>Figure 3. Connecting third-party apps.<\/figcaption><\/figure>\n<h2 class=\"regular-text\">The Next Evolution: An Attack Method Through SaaS<\/h2>\n<p>With this SaaS rootkit, threat actors can create malware that lives as a SaaS app and can infiltrate and maintain <a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint\/heroku-cyberattacker-stolen-oauth-token-customer-account-credentials\">access to a user&#8217;s account<\/a> while going unnoticed.<\/p>\n<p>While bad actors can&#8217;t find Exchange Legacy scopes that can used to add programmatically online hidden forwarding in the Microsoft UI, they can add them through a terminal script.<\/p>\n<p>The attacker&#8217;s job is simple: Create an app that looks credible, add the legacy scope protocols removed from the UI to the app (exploiting the vulnerability that the Adaptive Shield team uncovered), and send an offer to users to connect to it. The user will see an OAuth app dialogue box on the official Microsoft site, and many will likely accept it (Figure 4).<\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5ded57c225d58b4b\/63d2f0efc3ef490be0544a93\/BinFig4.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5ded57c225d58b4b\/63d2f0efc3ef490be0544a93\/BinFig4.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5ded57c225d58b4b\/63d2f0efc3ef490be0544a93\/BinFig4.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5ded57c225d58b4b\/63d2f0efc3ef490be0544a93\/BinFig4.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" alt=\"Figure 4. This screen shows a fake app permissions request.\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5ded57c225d58b4b\/63d2f0efc3ef490be0544a93\/BinFig4.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\">\n<\/picture><figcaption>Figure 4. This screen shows a fake app permissions request.<\/figcaption><\/figure>\n<p>Once a user accepts, the bad actor receives a token that grants permission to create forwarding rules and hides them from the user interface like a rootkit.<\/p>\n<p>An attack through these hidden forwarding rules should not be mistaken for a one-off attack but, rather, the start of a new attack method through SaaS apps.<\/p>\n<h2 class=\"regular-text\">Microsoft Response<\/h2>\n<p>In 2022, Adaptive Shield contacted Microsoft about the issue, Microsoft in response said that the issue has been flagged for future review by the product team as an opportunity to improve the security of the affected product.<\/p>\n<h2 class=\"regular-text\">How to Best Mitigate a SaaS Rootkit Attack<\/h2>\n<p>There&#8217;s no bulletproof way to eliminate SaaS rootkit attacks but there are a few best practices that can help keep organizations more protected.<\/p>\n<ul>\n<li><strong>Monitor third-party app access <\/strong>and their permissions to ensure that apps are legitimate and given only the access they require.<\/li>\n<li><strong>Track activities <\/strong>and be on the lookout for new inbox rules to identify any new connections from untrusted domains.<\/li>\n<li><strong>Disable third-party app registrations<\/strong> where possible to reduce risk.<\/li>\n<\/ul>\n<h2 class=\"regular-text\">Conclusion<\/h2>\n<p>Hidden forwarding rules are still a threat, even more so when they appear through the trusted Microsoft website. The traditional controls that were created to stop malware have struggled to keep up with the evolution of malware and the new attack vector that can exploit any SaaS app, from M365 to Salesforce to G-Workspace, etc. Organizations should utilize native security configurations to control the OAuth application installations across SaaS apps to protect users from malicious attacks like these.<\/p>\n<p>Get Forrester&#8217;s SSPM Report, &#8220;<a rel=\"nofollow sponsored noopener\" target=\"_blank\" href=\"https:\/\/go.adaptive-shield.com\/embrace-a-paradigm-shift-in-saas-protection-saas-security-posture-management-forrester-report\">Embrace aParadigm Shift In SaaS Protection: SaaS Security Posture Management<\/a>.&#8221;<\/p>\n<p><strong>About the Author<\/strong><\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6f8ee145598b12f6\/63d2eec4806ac967c153bf8f\/Native.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6f8ee145598b12f6\/63d2eec4806ac967c153bf8f\/Native.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6f8ee145598b12f6\/63d2eec4806ac967c153bf8f\/Native.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6f8ee145598b12f6\/63d2eec4806ac967c153bf8f\/Native.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt6f8ee145598b12f6\/63d2eec4806ac967c153bf8f\/Native.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\">\n<\/picture>\n<\/figure>\n<p>A former cybersecurity intelligence officer in the IDF, Maor Bin has over 16 years in cybersecurity leadership. In his career, he led SaaS Threat Detection Research at Proofpoint and won the operational excellence award during his IDI service. Maor got his B.Sc. in computer science and is CEO and co-founder of Adaptive Shield.<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/saas-rootkit-exploits-hidden-rules-in-microsoft-365-\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A vulnerability within Microsoft&#8217;s OAuth application registration allows an attacker to create hidden forwarding rules that act as a malicious SaaS rootkit.Read More <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/saas-rootkit-exploits-hidden-rules-in-microsoft-365-\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-50320","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SaaS RootKit Exploits Hidden Rules in Microsoft 365 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SaaS RootKit Exploits Hidden Rules in Microsoft 365 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-01-26T20:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"SaaS RootKit Exploits Hidden Rules in Microsoft 365\",\"datePublished\":\"2023-01-26T20:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/\"},\"wordCount\":827,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8812c9e1ca379428\\\/63d2f0356da77f6771bb2bb2\\\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/\",\"name\":\"SaaS RootKit Exploits Hidden Rules in Microsoft 365 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8812c9e1ca379428\\\/63d2f0356da77f6771bb2bb2\\\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"datePublished\":\"2023-01-26T20:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8812c9e1ca379428\\\/63d2f0356da77f6771bb2bb2\\\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt8812c9e1ca379428\\\/63d2f0356da77f6771bb2bb2\\\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SaaS RootKit Exploits Hidden Rules in Microsoft 365\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SaaS RootKit Exploits Hidden Rules in Microsoft 365 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/","og_locale":"en_US","og_type":"article","og_title":"SaaS RootKit Exploits Hidden Rules in Microsoft 365 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-01-26T20:00:00+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"SaaS RootKit Exploits Hidden Rules in Microsoft 365","datePublished":"2023-01-26T20:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/"},"wordCount":827,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/","url":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/","name":"SaaS RootKit Exploits Hidden Rules in Microsoft 365 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","datePublished":"2023-01-26T20:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt8812c9e1ca379428\/63d2f0356da77f6771bb2bb2\/BinFig1.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/saas-rootkit-exploits-hidden-rules-in-microsoft-365\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"SaaS RootKit Exploits Hidden Rules in Microsoft 365"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=50320"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50320\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=50320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=50320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=50320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}