Tag: Microsoft Teams phishing

Microsoft Teams phishing targets employees with A0Backdoor malware
News

Microsoft Teams phishing targets employees with A0Backdoor malware

Employees at financial and healthcare institutions were approached by hackers via Microsoft Teams in order to deceive them into allowing remote access via Quick Assist and install a brand-new malware known as A0Backdoor. By first bombarding the employee's inbox with spam and then contacting them over Teams while posing as the company's IT team and offering help with the unwanted communications, the attacker uses social engineering to acquire the employee's trust. The threat actor tells the user to launch a Quick Assist remote session in order to gain access to the target machine. This allows the malicious toolkit, which includes digitally signed MSI installers hosted in a personal Microsoft cloud storage account, to be deployed. Researchers at the cybersecurity firm BlueVoyant cl...
Ransomware access broker steals accounts via Microsoft Teams phishing
News

Ransomware access broker steals accounts via Microsoft Teams phishing

Microsoft claims that a ransomware group's go-to initial access broker has lately turned to Microsoft Teams phishing assaults to infiltrate corporate networks. Storm-0324, a malicious actor known to have previously used Sage and GandCrab ransomware, is the threat group responsible for this campaign's financial motivations. Additionally, after infiltrating business networks with the help of JSSLoader, Gozi, and Nymaim, Storm-0324 gave the famed FIN7 cybercrime group access. On the networks of its victims, FIN7 (also known as Sangria Tempest and ELBRUS) was detected installing Clop ransomware. In the past, it was connected to the now-defunct BlackMatter and DarkSide ransomware-as-a-service (Raas) operations as well as the Maze and REvil malware read more Ransomware access broker st...