Email Bombing, 'Vishing' Tactics Abound in Microsoft 365 Attacks
ID: 0036aa33-0ad3-5400-ac7f-c0b98e20f6dc
STIX ID: report--0036aa33-0ad3-5400-ac7f-c0b98e20f6dc
Feed Name: Dark Reading
Date Published: 2025-01-21
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Sophos X-Ops MDR is tracking two active ransomware campaigns (STAC5143 and STAC5777) that abuse Microsoft 365 — using Teams-based vishing and remote-control tools (Quick Assist/Teams screen sharing) combined with email bombing to overwhelm mailboxes and install Black Basta and Python ransomware; Sophos reports over 15 incidents, provides IOCs on GitHub, and recommends restricting external Teams calls and increasing employee awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
