Microsoft Teams phishing targets employees with A0Backdoor malware
Employees at financial and healthcare institutions were approached by hackers via Microsoft Teams in order to deceive them into allowing remote access via Quick Assist and install a brand-new malware known as A0Backdoor.
By first bombarding the employee's inbox with spam and then contacting them over Teams while posing as the company's IT team and offering help with the unwanted communications, the attacker uses social engineering to acquire the employee's trust.
The threat actor tells the user to launch a Quick Assist remote session in order to gain access to the target machine. This allows the malicious toolkit, which includes digitally signed MSI installers hosted in a personal Microsoft cloud storage account, to be deployed.
Researchers at the cybersecurity firm BlueVoyant cl...

