Security News > 2020 > November > Microsoft Teams Users Under Attack in ‘FakeUpdates’ Malware Campaign

Microsoft Teams Users Under Attack in ‘FakeUpdates’ Malware Campaign
2020-11-10 13:53

Attackers are using ads for fake Microsoft Teams updates to deploy backdoors, which use Cobalt Strike to infect companies' networks with malware.

In the advisory, Microsoft said it's seen attackers in the latest FakeUpdates campaign using search-engine ads to push top results for Teams software to a domain that they control and use for nefarious activity, according to the report.

The link also installs a valid copy of Microsoft Teams on the system to appear legitimate and avoid alerting victims to the attack.

In addition to the FakeUpdates campaigns that use Microsoft Teams lures, the tech giant also has seen similar attack patterns in at least six other campaigns with variations of the same theme, suggesting a broader attack by the same threat actors, according to the report.

Microsoft offered a number of mitigation techniques for the latest wave of FakeUpdates attacks.


News URL

https://threatpost.com/microsoft-teams-fakeupdates-malware/161071/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774