Microsoft Teams: The New Phishing Battlefront - How Attackers Are Exploiting Trusted Platforms
ID: d03a8409-8e78-5601-b340-b3e2c6d314be
STIX ID: report--d03a8409-8e78-5601-b340-b3e2c6d314be
Feed Name: KnowBe4 Blog
Researchers at AT&T Cybersecurity observed attackers abusing Microsoft Teams' External Access to send phishing messages from a compromised .onmicrosoft.com account. Recipients were lured into downloading a double-extension file named like a PDF ("Navigating Future Changes October 2023.pdf.msi"), which installed the DarkGate malware; investigators found three users who downloaded the suspicious file. The report highlights that default external access and visually legitimate onmicrosoft domains enable this vector and warns organizations to train employees and monitor for such indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
