logo

Microsoft Teams phishing pushes DarkGate malware via group chats

ID: 09fb755f-8d28-54eb-92c0-39cb4cf39846

STIX ID: report--09fb755f-8d28-54eb-92c0-39cb4cf39846

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-30

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

New phishing attacks abuse Microsoft Teams group chat invites to push DarkGate malware: attackers (likely using compromised Teams accounts) sent over 1,000 malicious group chat invites that trick recipients into downloading a double-extension MSI ('Navigating Future Changes October 2023.pdf.msi'); the installed DarkGate contacts a confirmed C2 domain (hgfdytrywq.com). The report describes DarkGate capabilities (concealed VNC, Windows Defender bypass, browser and Discord token theft, reverse proxy and file manager), notes similar past campaigns and actor/tool links (Storm-0324, APT29, TeamsPhisher), and recommends disabling External Access in Teams and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.