Threat Actors Poisoning SEO Results to Attack Organizations With Fake Microsoft Teams Installer
ID: a579f6de-f979-5090-ac5a-a00715869948
STIX ID: report--a579f6de-f979-5090-ac5a-a00715869948
Feed Name: cybersecurityNews.com
A search-engine-optimized SEO-poisoning campaign (active since November 2025) lures users to a typosquatted Microsoft Teams site (teamscn.com) to download a trojanized installer (MSTчamsSetup.zip / Setup.exe) that installs ValleyRAT. The multi-stage infection checks for 360 Total Security, uses PowerShell to add Windows Defender exclusions, executes a trojanized installer presented in Russian as a false flag, and installs a legitimate Teams client to hide malicious persistence; researchers attribute the campaign to the Chinese APT “Silver Fox” with high confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
