logo

Detecting Teams Chat Phishing Attacks (Black Basta)

ID: 1c3b5855-b172-5a86-aa3d-766b5a030edd

STIX ID: report--1c3b5855-b172-5a86-aa3d-766b5a030edd

Feed Name: NVISO Labs

Threat Score
75/100

Date Published: 2025-01-16

Date Updated: 2026-04-28

Author: Stamatis Chatzimangou

...
...

This report documents an ongoing Black Basta campaign where attackers first 'email-bomb' targets with benign spam and then impersonate Help Desk/IT via Microsoft Teams OneOnOne chats to persuade victims to grant remote access (native Quick Assist or third-party RMM), enabling lateral movement and ransomware deployment. It includes an illustrative attack flow, a KQL detection query to link email-bombing events to subsequent Teams ChatCreated events within a 3-hour window, detection opportunities, prevention recommendations (restrict external Teams chats, allow-list trusted domains, anti-spam policies), and references.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.