Microsoft is warning about an ongoing hacking campaign that begins with a message in Microsoft Teams and can end with ransomware and data theft.
According to a report published on the Microsoft blog, unnamed threat actors contact employees at various enterprises through Teams chats while impersonating IT staff. They pressure victims into granting remote access through screen sharing or remote monitoring and management tools. Once access is obtained, the attackers install malware loaders and other implants.
The malware enables further activity, including host reconnaissance, discovery of security products and virtualization, and periodic desktop screen capture. The attackers also enumerate domain accounts, servers, and users using native tools and Active Directory Service Interfaces (ADSI) queries before moving laterally through the network.
The campaign’s final stages involve identifying and extracting valuable data, followed by a ransomware infection. Microsoft does not identify the perpetrators and says the fake IT-support technique is used by multiple groups, including Russia’s Cozy Bear, FIN7, and Storm-1811. ShinyHunters is also known to use Teams to obtain access, although it rarely deploys an encryptor and instead focuses on data exfiltration.
Microsoft urges enterprises to strengthen employee training, establish internal helpdesk authentication phrases, verify unsolicited support contacts, and harden Teams and email against social engineering. It also recommends Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP).
Comments
0No comments yet. Be the first to comment.