Varonis found that an attacker who has already compromised a highly privileged Entra account can register a rogue External Authentication Method (EAM) as one of these external MFA providers and use it to insert a convincing Microsoft password prompt into the legitimate authentication flow.
The fake prompt captures the user's password in plaintext before the malicious provider returns a valid signed token to Entra, causing the login to complete without displaying an error.
Yeah obviously if the account that configures the EAM is compromised then all bets are off. This isn't exactly an attack is it, it's just an observation about the trust model.
Those actions require a Global Administrator or Authentication Policy Administrator account, making TrustSink a post-compromise technique.
"If you've already been compromised then you're fucked" isn't the kind of research that deserves its own catchy name and blog post article. Is this what passes for security research these days?