office-cli is a Linux command-line email-collection and exfiltration utility used to obtain unauthorized access to Microsoft 365 Outlook mailboxes. It automates repeated retrieval of messages from different time periods and stores collected email locally in account-specific subdirectories. Operators execute it directly or through Bash scripts, using JSON configuration files containing application client identifiers, tenant identifiers, and client secrets. Targeted accounts are periodically updated to support ongoing collection. The utility uses legitimate mailbox-access mechanisms to reduce detection.
Its use is associated with Chinese government-linked actors enabled by Integrity Technology Group, whose techniques overlap with activity tracked as Flax Typhoon, Ethereal Panda, and Red Juliett; these attribution labels are not necessarily interchangeable. The associated email-theft operations have affected government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, within broader campaigns targeting organizations in Africa and North America and U.S. critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Data theft combines Curlc4.txt and office-cli email collection with DCSync credential harvesting through DC.exe.
The actors use office-cli, a Linux command-line tool, to automate the collection and exfiltration of email from Microsoft Outlook 365 accounts across different time periods.
“The threat actors use a command-line utility office-cli ... to continuously target and access Microsoft Outlook 365 email accounts to exfiltrate emails across different time periods.”
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named tool used for email collection in the described data-theft activity. The content does not provide implementation details or identify a broader malware family.
Command-line tool used for automated email collection and exfiltration. It reads mailbox-access settings, including client_id, tenant_id, and secret, from JSON configuration files and stores collected messages in subdirectories beneath a dump directory. Operators periodically update the targeted accounts.
A command-line tool explicitly described as enabling unauthorized access to mailbox data during the reported intrusions. It is included for its malicious use, not because the reference establishes it as an inherently malicious software family.
An email collection tool that repeatedly accesses Microsoft 365 accounts to retrieve messages from different periods. It uses configuration files containing a client ID, tenant ID, and secret, and relies on legitimate access methods to reduce detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.