Email Bombing and Fake IT Support Calls Fuel New Microsoft Teams Phishing Attacks
ID: 718b9a54-217d-5c89-a23e-f8eb73aa8be3
STIX ID: report--718b9a54-217d-5c89-a23e-f8eb73aa8be3
Feed Name: cybersecurityNews.com
A growing 2024–2026 campaign leverages email-bombing to panic victims, then uses Microsoft Teams accounts impersonating internal IT to request remote-access assistance; once access is granted attackers use legitimate remote-support tools (Quick Assist, AnyDesk) and file-transfer utilities (WinSCP) or malicious Java payloads to exfiltrate data. The activity is linked to known groups (Scattered Spider, Payouts King, UNC6692) and backed by organized infrastructure hosted at bulletproof providers, and the report recommends restricting external Teams collaboration and blocking unnecessary remote-access/file-transfer tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
