logo

Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor

ID: fbb23c8f-48e4-5eeb-806b-e8878a1cb00f

STIX ID: report--fbb23c8f-48e4-5eeb-806b-e8878a1cb00f

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A0Backdoor is a newly identified backdoor used in a targeted social-engineering campaign that leverages Microsoft Teams and Quick Assist to obtain remote access; attackers deliver digitally signed MSI installers that sideload a malicious hostfxr.dll to run encrypted shellcode and establish DNS-based C2 (MX queries and DNS tunneling). The campaign, active from at least August 2025 to February 2026, targets finance and healthcare professionals, uses code-signing certificates and lapsed domains to evade detection, and is linked to threat actors associated with the Black Basta ransomware network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.