TI Mindmap HUB
Threat Intelligence Report

TrustSink: How a Rogue External MFA Provider Steals Passwords

📅 September 16, 2026 📰 www.varonis.com 🔍 0 CVE(s) referenced

TrustSink is a post-compromise attack technique that allows a rogue external MFA provider to persistently harvest plaintext passwords during legitimate Microsoft Entra sign-ins—even after password resets—by inserting a convincing credential prompt into the authentication flow, making detection and removal of the rogue provider critical for defense.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle