logo

Phishing in Teams: the new ransomware frontline

ID: a7dac3d2-6aee-5be3-b370-deefad58bae6

STIX ID: report--a7dac3d2-6aee-5be3-b370-deefad58bae6

Feed Name: Expel Blog

Threat Score
72/100

Date Published: 2025-04-25

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Expel observed a surge in a Microsoft Teams-based phishing campaign targeting organizations (retail, real estate) where attackers social-engineer users to grant remote access (commonly via QuickAssist), then deploy remote access tools, custom Python reverse proxies or SSH reverse tunnels to reach attacker infrastructure; IoCs (IPs, file hashes, Teams account names) and mitigations (restrict external Teams invitations, disable QuickAssist, enable auto-remediation) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.