Beyond Email: Attackers Hijack Microsoft Teams External Access to Launch Deep Network Compromise
ID: c058bd82-508d-5b6c-b36b-51c8cf4d3eca
STIX ID: report--c058bd82-508d-5b6c-b36b-51c8cf4d3eca
Feed Name: securityonline.info
Rapid7 Labs details a targeted corporate breach where an attacker leveraged Microsoft Teams external access and social engineering to deliver a Python payload, escalated privileges using CVE-2023-36036, captured domain credentials via a fake lock-screen overlay, performed Kerberoasting and memory acquisition with Dumpit, and exfiltrated the resulting RAM dump through an anonymous file-hosting service; the report highlights collaboration platforms as a rising attack surface and recommends tightening external access policies, patching privilege escalation vectors, monitoring for memory imaging tools, and blocking anonymous file-sharing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
