Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
365-Stealer — Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious Outlook rules via a CLI and web management portal. | Kitploit
Tools/GitHubGitHub/alteredsecurity/365-stealer
PhishingPenetration TestingCloud SecurityRed Teaming
GitHubalteredsecurity/365-stealer

365-Stealer

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious Outlook rules via a CLI and web management portal.

View Repository
584111526 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

365-Stealer

365-Stealer

Table of Contents

  • About 365-Stealer
  • About Illicit Consent Grant Attack
  • Key Features of 365-Stealer
  • Setup Attacking Environment
    • Automated Azure App Registration
    • Manual Azure App Registration
    • Configuring the Application
      • Creating Client Secrets
      • Adding API Permissions
  • Setting Up 365-Stealer
    • Enabling SQLite3 on the Apache Server
  • Configuring the 365-Stealer Management Portal
    • Modifying Paths
    • Enabling IP Whitelisting for the 365-Stealer Management Portal
  • OPSEC Consideration
  • Command Line Help
  • Blog
  • Bugs and Feature Requests
  • Contributing

About

365-Stealer is a Python3-based tool designed to automate illicit consent grant attacks. When a target user unknowingly grants permission to an attacker's application, the attacker gains access to the victim's refresh token. This refresh token can then be used to generate other tokens, allowing the attacker to access sensitive data such as emails, files on OneDrive, and notes—without needing further input from the victim. Manually exploiting this can be time-consuming, but 365-Stealer simplifies and automates the process.

365-Stealer comes with 2 interfaces:

  1. CLI (Command Line Interface) - Built entirely in Python3, the CLI provides direct access to the tool’s features.
  2. Web UI - The Web User Interface is developed using PHP, while Python3 operates in the background to execute commands.

Understanding the Illicit Consent Grant Attack

An illicit consent grant attack occurs when an attacker registers a malicious application within Azure, requesting access to sensitive data like contacts, emails, or documents. The attacker deceives a user into consenting to the app, usually by presenting it as legitimate. Once the victim clicks "Accept," they unknowingly provide access to the attacker, allowing them to act on behalf of the victim without needing the victim’s organizational credentials.

To explain more clearly, once the user grants permission, Entra ID sends a token to the attacker's server. This token gives the attacker the ability to read emails, send emails, access files on OneDrive, and perform other malicious activities using the victim's credentials. Unlike phishing attacks that rely on stealing passwords, illicit consent grant attacks bypass authentication entirely by abusing the permissions system of cloud applications.

Key Features of 365-Stealer

  • Steals Refresh Tokens: The tool captures refresh tokens from victims, which can be used to generate new access tokens for at least 90 days, providing ongoing access to their accounts..
  • Send Emails on Behalf of Victims: 365-Stealer can send emails with attachments from the victim’s account to other users without their knowledge.
  • Create Malicious Outlook Rules: It can create harmful rules in the victim’s Outlook, such as forwarding any incoming mail to an attacker-controlled email.
  • Upload Files to OneDrive: The tool can upload any file into the victim's OneDrive account.
  • Steal Data from OneDrive, OneNote, and Email: 365-Stealer can extract files from OneDrive, OneNote, and dump all emails, including attachments, from the victim’s account.
  • Manage Stolen Data: The 365-Stealer Management Portal allows attackers to manage all compromised data, including refresh tokens, emails, files, and users.
  • Backdoor OneDrive Documents: The tool can backdoor a .docx file stored in OneDrive by injecting malicious macros and replacing the file extension with .doc.
  • Store Compromised Data: All collected information, such as refresh tokens, emails, files, and user data from the victim’s tenant, along with configurations, are stored in a database.
  • Customizable Delay for Data Theft: Attackers can delay requests by specifying a time in seconds to avoid detection while stealing data.
  • Host a Phishing Application: The tool can host a fake application for performing illicit consent grant attacks using the --run-app command in the terminal or via the 365-Stealer Management portal.
  • Selective Token Theft: Using the --no-stealing flag, the tool can steal only the tokens without further actions, allowing attackers to exploit them later.
  • Request New Access Tokens: The tool allows attackers to request new access tokens for all users or specific users within the compromised tenant.
  • Generate Access Tokens Using Credentials: With the --refresh-token, --client-id, and --client-secret flags, attackers can easily obtain new access tokens.
  • Automate Azure App Registration: The --app-registration flag automates the process of Azure app registration, making it easier to set up the attack infrastructure without manual intervention.
  • Selective Data Theft: With the --custom-steal flag, attackers can selectively steal data from specific sources like OneDrive, Outlook, etc.
  • Shared Data: All compromised data is saved in a database.db file, which can be shared with our team to leverage the existing stolen tokens and data.
  • Search and Filter Emails: Attackers can search for specific emails by keyword, subject, user’s email address, or filter emails with attachments using the 365-Stealer Management portal.
  • Export User Data: The tool allows attackers to dump user information from the compromised tenant and export the data to a CSV file for further analysis or use.

Setting Up the Attack Environment

Automated Azure App Registration

To automatically register an application in Azure using the provided Python script, follow these steps:

  1. Ensure you have Python3 installed on your machine.

  2. Clone the 365-Stealer repository:

    git clone https://github.com/AlteredSecurity/365-Stealer.git
    cd 365-Stealer
    
  3. Install the required Python modules:

    pip install -r requirements.txt
    
  4. Run the automated Azure app registration script:

    python 365-Stealer.py --app-registration
    
  • The script will prompt you to provide your Azure tenant ID, the desired application name, and the redirect URI.
  • You will also choose an authentication method (OAuth with Client Secret or Device Code Flow) and set API permissions (either default, LowImpact or custom permissions).
  • Follow the prompts to complete the app registration process.

Manual Azure App Registration

If you prefer to manually register an Azure application, follow these steps:

Download Tool