Microsoft Teams phishing pushes DarkGate malware via group chats
ID: 09fb755f-8d28-54eb-92c0-39cb4cf39846
STIX ID: report--09fb755f-8d28-54eb-92c0-39cb4cf39846
Feed Name: Bleeping Computer
New phishing attacks abuse Microsoft Teams group chat invites to push DarkGate malware: attackers (likely using compromised Teams accounts) sent over 1,000 malicious group chat invites that trick recipients into downloading a double-extension MSI ('Navigating Future Changes October 2023.pdf.msi'); the installed DarkGate contacts a confirmed C2 domain (hgfdytrywq.com). The report describes DarkGate capabilities (concealed VNC, Windows Defender bypass, browser and Discord token theft, reverse proxy and file manager), notes similar past campaigns and actor/tool links (Storm-0324, APT29, TeamsPhisher), and recommends disabling External Access in Teams and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
