logo

Microsoft disrupts ransomware attacks targeting Teams users

ID: 3acace38-9436-5703-9ee9-bbe2da7a3d4f

STIX ID: report--3acace38-9436-5703-9ee9-bbe2da7a3d4f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-16

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Microsoft disrupted a wave of attacks by the financially motivated group Vanilla Tempest (also tracked as VICE SPIDER/Vice Society) that used malvertising and SEO-poisoned search ads to push fake Microsoft Teams installers (MSTeamsSetup.exe) from lookalike domains; the installers were signed with trusted certificates and deployed the Oyster backdoor to enable remote access, data theft, and the deployment of Rhysida ransomware. Microsoft revoked over 200 malicious certificates after discovering the campaign, which has targeted sectors including education, healthcare, IT, and manufacturing and has used code-signing services from multiple providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.