logo

Microsoft Teams phishing targets employees with A0Backdoor malware

ID: 7a364061-ad76-5df3-8507-3045f6bbd47e

STIX ID: report--7a364061-ad76-5df3-8507-3045f6bbd47e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at BlueVoyant describe a targeted campaign that impersonates corporate IT over Microsoft Teams to convince employees to start Quick Assist sessions and install malicious, digitally signed MSI installers that deploy A0Backdoor via DLL sideloading. The backdoor performs host fingerprinting, sandbox detection, and uses DNS MX queries to exchange encoded C2 data; BlueVoyant links the activity to tactics associated with the BlackBasta operation and reports targets in the financial and healthcare sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.