logo

Email Bombing, 'Vishing' Tactics Abound in Microsoft 365 Attacks

ID: 0036aa33-0ad3-5400-ac7f-c0b98e20f6dc

STIX ID: report--0036aa33-0ad3-5400-ac7f-c0b98e20f6dc

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-21

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Sophos X-Ops MDR is tracking two active ransomware campaigns (STAC5143 and STAC5777) that abuse Microsoft 365 — using Teams-based vishing and remote-control tools (Quick Assist/Teams screen sharing) combined with email bombing to overwhelm mailboxes and install Black Basta and Python ransomware; Sophos reports over 15 incidents, provides IOCs on GitHub, and recommends restricting external Teams calls and increasing employee awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.