Ransomware groups impersonate tech support in Microsoft Teams phishing attack

Search for a command to run...

No comments yet. Be the first to comment.
Chuyện Gì Đang Xảy Ra? Hãy tưởng tượng thế này: bạn đang ngồi làm việc trên máy tính, soạn email, lướt web, mở tài khoản ngân hàng kiểm tra số dư. Mọi thứ đều bình thường. Không có cửa sổ lạ nào bật l

What's Going On? Imagine this: you're sitting at your computer, composing emails, surfing the web, opening a bank account to check the balance. Everything is normal. No strange windows pop up. There a

Tổng Quan SourTrade là chiến dịch malvertising quy mô lớn đang hoạt động từ cuối 2024, nhắm vào nhà đầu tư crypto và trader tại 12 quốc gia trên 25 ngôn ngữ. Kẻ tấn công giả mạo ba nền tảng được tin d

Overview SourTrade is a large-scale malvertising campaign running since late 2024, targeting crypto investors and traders in 12 countries across 25 languages. The attacker impersonates three trusted p

Tổng Quan Hãy hình dung kịch bản này: bạn vừa check-in khách sạn sau chuyến bay dài, mở laptop, bật Wi-Fi, mở Chrome và Chrome tự mở trang đăng nhập Microsoft 365. Trông quen thuộc. Bạn gõ mật khẩu, b

Cybercrime groups specializing in ransomware are increasingly employing more sophisticated tactics to infiltrate organizational systems. They are utilizing a combination of mass spam email campaigns and impersonating tech support staff via the Microsoft Teams app to deceive victims into granting remote access and installing malware.
This tactic has been observed since late last year in attacks associated with the Black Basta ransomware. Recently, security researchers at Sophos have also identified that other criminal groups, potentially linked to the FIN7 group, are using similar methods.
To reach employees of targeted companies, attackers exploit the default configuration of Microsoft Teams at the targeted organization, which allows calls and chats from external domains. The attack process usually unfolds in three main stages:
Email Bombing: Sending thousands of spam emails in a short time to create confusion and distract the victim.
Impersonating IT Support: Using Microsoft Teams to contact the victim, pretending to be IT support staff.
Installing Malware: Tricking the victim into granting remote access and installing malicious tools.
Begins by sending about 3,000 spam emails within 45 minutes.
Then, the victim receives an external call via Microsoft Teams from an account named "Support Department Manager."
The victim is convinced to set up a remote screen control session through Microsoft Teams.
The attacker drops a Java archive file (MailQueue-Handler.jar) and Python scripts (RPivot backdoor) stored on an external SharePoint link.
The malware creates an encrypted command and control (C2) communication channel with external IP addresses, giving the attacker remote access to the compromised computer.
Also begins with sending spam emails followed by Microsoft Teams messages, claiming to be from the tech support department.
The victim is tricked into installing Microsoft Quick Assist to give the attacker direct keyboard access.
Malware (winhttp.dll) is loaded alongside the legitimate Microsoft OneDriveStandaloneUpdater.exe process.
This malware records the victim's keystrokes, collects stored login information from files and the registry, and scans the network for potential pivot points.
Sophos has observed some signs that there may be a connection between campaign STAC5143 and the notorious FIN7 group. Specifically:
The use of RPivot has been seen in previous FIN7 attacks.
Code obfuscation techniques have been used before in FIN7 campaigns.
As these tactics become more common in the ransomware space, organizations should consider:
Disabling Quick Assist in critical environments.
Raising cybersecurity awareness among employees about phishing attacks via Microsoft Teams.
Implementing strong protective measures like Endpoint Detection and Response (EDR) solutions to identify malicious activity.
Monitoring network traffic to detect unusual patterns that may indicate ransomware activity.