Tag

Microsoft Teams

All articles tagged with #microsoft teams

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America
security26 days ago

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America

Sophos warns of STAC4749, a vishing campaign in which external Microsoft Teams calls impersonate IT staff to gain remote access, deploying backdoors and culminating in Chaos ransomware across dozens of North American organizations (Canada ~50%, US ~45%). Attackers used fake IT domains under the .top TLD, relied on Quick Assist or RemSupp, then PowerShell to install persistence and remote access tools like DWAgent/AnyDesk, with RDP used for lateral movement. Ransomware encrypts files and may accompany data theft; Chaos-as-a-service is linked to Conti offshoots. The techniques evolved to evade detection; no confirmed link to MuddyWater.

DragonForce Hides C2 Traffic in Microsoft Teams Relays with Backdoor.Turn
technology2 months ago

DragonForce Hides C2 Traffic in Microsoft Teams Relays with Backdoor.Turn

DragonForce-linked Backdoor.Turn uses Microsoft Teams’ TURN relay to hide its command-and-control traffic, obtaining an anonymous Teams token and establishing a QUIC connection to the attacker’s C2 server. The intrusion into a major U.S. services firm began with a BYOVD/DLL side-loading chain and included injection into DbgView64.exe for persistence, with initial access likely via an SQL/MS-SQL flaw or an initial access broker. The actors remained on the network for 1–2 months, illustrating a shift toward sophisticated, cartel-like ransomware operations.

Teams adds Wi‑Fi presence to auto-scan office locations
technology2 months ago

Teams adds Wi‑Fi presence to auto-scan office locations

Microsoft Teams is rolling out a feature called Workplace Check-in via Wi‑Fi that automatically updates a user’s work location when they connect to the organization’s corporate Wi‑Fi. The general availability rollout began in June 2026 (Roadmap ID 488800), extending the existing manual check-in by passively surfacing location within Teams. It’s available on Desktop and Mac across Worldwide Standard multi-tenant instances, but disabled by default and controlled by tenant admins. Users can opt in or out, ensuring a privacy-forward approach while helping coordinate in-person collaboration in hybrid work environments.

Ransomware hides C2 traffic in Teams relays to evade detection
technology2 months ago

Ransomware hides C2 traffic in Teams relays to evade detection

Symantec reports DragonForce’s Go-based Backdoor.Turn ransomware is the first in-the-wild malware to abuse Microsoft Teams TURN relays to conceal its command-and-control traffic. After initial access via an SQL server vulnerability, the group used BYOVD drivers for kernel privileges, established persistence, exfiltrated data, and then deployed DragonForce ransomware, leveraging sophisticated tradecraft and publishing IoCs for defenders.

MuddyWater Uses Teams to Harvest Credentials and Subvert MFA in Chaos False-Flag Campaign
cybersecurity3 months ago

MuddyWater Uses Teams to Harvest Credentials and Subvert MFA in Chaos False-Flag Campaign

Security researchers describe a MuddyWater operation that exploited Microsoft Teams for external contact and screen-sharing to harvest user credentials (credentials.txt/cred.txt) and push MFA changes, followed by backdoor access using DWAgent and AnyDesk. The attackers deployed a custom RAT (Game.exe) and used C2 domains linked to MuddyWater, framing the intrusion as a Chaos ransomware false-flag campaign focused on credential theft and data exfiltration rather than encryption. The campaign featured indicators like a forged code-signing certificate and stolen credentials enabling lateral movement to Domain Controllers.

MuddyWater Uses Teams for Credential Theft in False-Flag Ransomware Operation
technology3 months ago

MuddyWater Uses Teams for Credential Theft in False-Flag Ransomware Operation

Rapid7 links MuddyWater to a 2026 operation that used interactive Teams screen-sharing to harvest credentials and bypass MFA, exfiltrate data, and maintain persistence with tools like DWAgent and AnyDesk, while avoiding file encryption to masquerade as a ransomware attack. Described as a false-flag, state-backed campaign, it leverages a Chaos RaaS framework and off-the-shelf tools to blur attribution, highlighting evolving attacker tradecraft that blends cybercrime with strategic aims.

Threat Actors Weaponize Teams Messaging to Breach Enterprises
cyber-security-news4 months ago

Threat Actors Weaponize Teams Messaging to Breach Enterprises

UNC6692 runs a multistage intrusion that begins with mass email bombardment and escalates via impersonation of IT staff in Microsoft Teams, guiding victims to a phishing landing page hosted on AWS S3. The campaign then harvests credentials, deploys a modular malware suite (SNOWBELT), and uses cloud-based C2 and data staging to exfiltrate data and compromise domain controllers, highlighting the need to restrict external Teams access and monitor cloud egress and browser extensions for anomalous activity.

Teams Tactics Drive UNC6692’s Modular SNOW Malware Campaign
technology4 months ago

Teams Tactics Drive UNC6692’s Modular SNOW Malware Campaign

Security researchers describe UNC6692’s two-stage assault: a flood of spam to overwhelm inboxes followed by impersonating IT staff via Microsoft Teams to coax victims into installing a patch that drops the SNOWBELT/SNOWGLAZE/SNOWBASIN malware suite for remote access, lateral movement, and data exfiltration, leveraging cloud services for C2 and payload delivery. The campaign targets executives and uses WebSocket tunnels and backdoors to expand access, with defenders urged to harden collaboration tools and enforce verified help-desk procedures.

Teams adds brand-impersonation warnings for external calls
technology7 months ago

Teams adds brand-impersonation warnings for external calls

Microsoft will roll out Brand Impersonation Protection for Teams Calling, automatically warning users on first-time external calls that try to impersonate trusted brands. Enabled by default in the targeted release mid-February, the feature lets users accept, block, or end flagged calls, with alerts possibly persisting during a conversation. It aims to curb social-engineering attacks and complements other security updates; no admin action is required for activation, though IT should update training materials.

Microsoft outage hits Outlook and Teams as investigators probe network issues
technology7 months ago

Microsoft outage hits Outlook and Teams as investigators probe network issues

Microsoft 365 services including Outlook, Teams and other apps experienced a widespread outage after thousands reported issues on Downdetector; Microsoft said it was investigating and cited a possible third‑party networking issue. By about 18:44 UTC the company said the incident was resolved and the service environment remained healthy, though a small number of users continued to report sign‑in or access problems (with some Xbox app/store issues on iPad).

Microsoft Teams to Implement Enhanced Security Features and External User Controls by January 2026
technology8 months ago

Microsoft Teams to Implement Enhanced Security Features and External User Controls by January 2026

Microsoft Teams will soon allow security admins to block external users from messaging or calling within Teams via integration with Defender for Office 365, enhancing security and control over external communications. The feature, rolling out in January 2026, supports managing up to 4,000 blocked domains and 200 email addresses, and aims to prevent cyberattacks like social engineering and ransomware.

Microsoft Teams Vulnerabilities Enable Impersonation, Message Tampering, and Data Theft
technology9 months ago

Microsoft Teams Vulnerabilities Enable Impersonation, Message Tampering, and Data Theft

Cybersecurity researchers revealed four security vulnerabilities in Microsoft Teams that could allow attackers to impersonate colleagues, manipulate messages without detection, and exploit notifications, posing significant social engineering risks. Some issues have been patched, but the flaws highlight the importance of securing collaboration tools against trust-based attacks, especially as threat actors increasingly target enterprise communication platforms.