<t>This needs to be seriously upvoted and made into a issue, seeing this so oftenly it's getting frustrating. <br/>
<br/>
I've even tore it all apart and know how it all works now, even the malware code. They use VBA macros to create rules on the mailboxes, another VBA which creates a authentication window which looks like the Outlook prompt which just sends them the creds, and then have a bot sign into Office365 and enter a forwarding address into the O365 User Control Panel.<br/>
<br/>
I've now PowerShell'd it all from a secure station which checks all our tenants from one account and creates reports and stuff, takes ages though.<br/>
<br/>
P.S Have you lot noticed slowness in the responsiveness in their Powershell backend recently?</t>