logo

Threat Actors Poisoning SEO Results to Attack Organizations With Fake Microsoft Teams Installer

ID: a579f6de-f979-5090-ac5a-a00715869948

STIX ID: report--a579f6de-f979-5090-ac5a-a00715869948

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A search-engine-optimized SEO-poisoning campaign (active since November 2025) lures users to a typosquatted Microsoft Teams site (teamscn.com) to download a trojanized installer (MSTчamsSetup.zip / Setup.exe) that installs ValleyRAT. The multi-stage infection checks for 360 Total Security, uses PowerShell to add Windows Defender exclusions, executes a trojanized installer presented in Russian as a false flag, and installs a legitimate Teams client to hide malicious persistence; researchers attribute the campaign to the Chinese APT “Silver Fox” with high confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.