Ransomware scum make it personal for <i>Reg</i> readers by impersonating tech support
ID: 61bf0f69-342b-5970-bd67-275308321b24
STIX ID: report--61bf0f69-342b-5970-bd67-275308321b24
Feed Name: The Register (Security)
Sophos MDR tracked two separate campaigns exploiting default Microsoft Teams configurations and malicious Office 365 tenants to deliver remote-access attacks: STAC5143 used spam, Teams vishing, a Java-to-PowerShell/7zip chain, side-loaded DLLs and Python backdoors (with RPivot) and is assessed as possibly linked to FIN7; STAC5777 combined mass spam and Quick Assist-based remote takeover to harvest credentials, establish C2 via legitimate processes and attempt Black Basta ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
