logo

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

ID: 443a4ed4-47a0-5ff5-a1ac-eafc45022a3c

STIX ID: report--443a4ed4-47a0-5ff5-a1ac-eafc45022a3c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

BlueVoyant reports an ongoing social-engineering campaign where attackers impersonate IT support over Microsoft Teams and convince victims to use Quick Assist, then deploy digitally signed MSI installers that perform DLL sideloading to install a memory-resident backdoor named A0Backdoor which uses covert DNS MX lookups for command-and-control; the activity ties to prior Storm-1811/Black Basta operations and employs sophisticated anti-analysis and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.