logo

Sliding into your DMs: Abusing Microsoft Teams for Malware Delivery

ID: a68a6158-f058-58f3-9243-ff0ef855f1bf

STIX ID: report--a68a6158-f058-58f3-9243-ff0ef855f1bf

Feed Name: Cloud Chronicles

Threat Score
75/100

Date Published: 2025-08-28

Date Updated: 2026-07-29

Author: Isuf Deliu

...
...

This report documents a Microsoft Teams–centric social-engineering campaign where attackers impersonate IT support to coerce victims into installing remote access tools and executing a PowerShell-based multi-stage payload that harvests system information, prompts for credentials, establishes persistence (scheduled tasks or registry autorun), and communicates with AES-encrypted C2 infrastructure; the analysis includes technical details, IOCs (domains, IPs, mutex, crypto constants, user display names), and detection guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.