logo

Microsoft Teams: The New Phishing Battlefront - How Attackers Are Exploiting Trusted Platforms

ID: d03a8409-8e78-5601-b340-b3e2c6d314be

STIX ID: report--d03a8409-8e78-5601-b340-b3e2c6d314be

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2024-02-01

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Researchers at AT&T Cybersecurity observed attackers abusing Microsoft Teams' External Access to send phishing messages from a compromised .onmicrosoft.com account. Recipients were lured into downloading a double-extension file named like a PDF ("Navigating Future Changes October 2023.pdf.msi"), which installed the DarkGate malware; investigators found three users who downloaded the suspicious file. The report highlights that default external access and visually legitimate onmicrosoft domains enable this vector and warns organizations to train employees and monitor for such indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.