Security News > 2023 > September > Ransomware access broker steals accounts via Microsoft Teams phishing
Microsoft says an initial access broker known for working with ransomware groups has recently switched to Microsoft Teams phishing attacks to breach corporate networks.
"In July 2023, Storm-0324 began using phishing lures sent over Teams with malicious links leading to a malicious SharePoint-hosted file," Microsoft said on Tuesday.
According to Redmond, threat actors using these Teams phishing tactics are now recognized as "EXTERNAL" users when external access is enabled within an organization's settings.
After detecting Storm-0324's Teams phishing attacks, Microsoft suspended all tenants and accounts they used in the campaign.
Microsoft Teams phishing attack pushes DarkGate malware.
Russian hackers target govt orgs in Microsoft Teams phishing attacks.
News URL
Related news
- Black Basta ransomware poses as IT support on Microsoft Teams to breach networks (source)
- Ransomware gang using stolen Microsoft Entra ID creds to bust into the cloud (source)
- Ransomware attackers hop from on-premises systems to cloud to compromise Microsoft 365 accounts (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- Microsoft says more ransomware stopped before reaching encryption (source)
- Microsoft: Ransomware Attacks Growing More Dangerous, Complex (source)
- Black Basta poses as IT support on Microsoft Teams to breach networks (source)
- Black Basta operators phish employees via Microsoft Teams (source)
- Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams (source)