TrustSink Attack Exploits Microsoft Entra MFA to Steal Passwords
Researchers at Varonis Threat Labs have demonstrated a technique called TrustSink that exploits a vulnerability in Microsoft Entra's multi-factor authentication (MFA) system. The attack relies on an attacker gaining control of a privileged Entra account, such as a Global Administrator or Authentication Policy Administrator.
The attacker then registers a rogue External Authentication Method (EAM) and configures it as a trusted authentication provider. When a user attempts to log in, the EAM presents a convincing replica of Microsoft's password prompt, captures the replacement password, and returns a valid signed token allowing the login to continue.
What makes TrustSink particularly difficult to detect is that it does not start with phishing. The attacker must already have control over a privileged Entra account before deploying the technique. This means security teams need to monitor not only who authenticated but also who changed how authentication works.