home.social

#microsoftteams — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #microsoftteams, aggregated by home.social.

fetched live
  1. "- We discovered a new malware family which consists of a modular loader and an array of unique memory-resident components, all of which bridge multiple programming languages to avoid detection.

    - By reverse engineering the malware and emulating the command-and-control protocol, we were able to lure the threat actors into attempting a hands-on-keyboard attack against our fake network, enabling us to obtain a significant portion of their tooling.

    - The original attack chain was distributed by a Microsoft Teams phishing technique in which the attacker posed as a member of the company’s IT helpdesk.

    - The malware attempts to phish the user’s system login credentials by creating a fake lock screen. It then loads a network tunneling module to enable the threat actors to log into internal and external company systems via the infected user’s machine."

    expel.com/blog/synkloader-when

    #CyberSecurity #Malware #Microsoft #MicrosoftTeams #MSTeams

  2. SynkLoader: when you throw in everything but the kitchen sink

    A sophisticated modular loader utilizing multiple programming languages to evade detection has been discovered. The attack begins with Microsoft Teams phishing where attackers impersonate IT helpdesk personnel, convincing targets to install a fake PowerShell cleaner via MSI installer. The malware deploys memory-resident components bridging Python, C#, C++, and PowerShell to profile systems, establish persistence via scheduled tasks, and deploy a fake Windows lock screen to phish user credentials. Additional modules include a reverse proxy for network tunneling, enabling threat actors to access internal corporate systems using compromised credentials, plus remote shell and VNC capabilities for hands-on-keyboard attacks. The elaborate multi-stage infection chain suggests potential ransomware operations or initial access brokering.

    Pulse ID: 6a87b22b1fbf04df7046d537
    Pulse Link: otx.alienvault.com/pulse/6a87b
    Pulse Author: AlienVault
    Created: 2026-08-21 02:04:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Malware #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #Phishing #PowerShell #Proxy #Python #RAT #RansomWare #ReverseProxy #VNC #Windows #bot #AlienVault

  3. Microsoft bringt neue Funktionen für #MicrosoftTeams. Bald lassen sich Benachrichtigungen mit einem Klick pausieren und Organisatoren von Meetings unkompliziert wechseln. #Software winfuture.de/news,160726.html?

  4. Video: Diese europäischen Videocall-Dienste solltet ihr euch ansehen

    Nutzerdaten aus Microsoft Teams oder Zoom könnten unbemerkt in den USA landen. Der Grund: der US-Cloud-Act. Wir stellen sieben europäische Alternativen vor.

    heise.de/news/Video-Diese-euro

    #DigitaleSouveränität #Groupware #IT #MicrosoftTeams #Video #news

  5. Teams is so bad and illuminates a #microsoft pathology. I'm a guest on a call and forced to use #MicrosoftTeams It just grabbed a random profile on my desktop - there's no guest option, no opt-in, they just grab it. So I'm on a call right now **as two of my cats** (who own the family calendar). Microsoft think they might even have found the #catsofMastodon #linkedin account where Alex and Prudence have probably been congratulating one another on recent promotions.

  6. Microsoft Teams Vishing Campaign Leads to Chaos Ransomware Deployment

    STAC4749 is a financially motivated Teams-based vishing campaign in which attackers impersonate IT support to gain remote access through Quick Assist or RemSupp. They then deploy malware, establish persistence, move laterally, and ultimately deploy Chaos ransomware.

    Pulse ID: 6a6ca07a1a3d8bfabd6d9941
    Pulse Link: otx.alienvault.com/pulse/6a6ca
    Pulse Author: cryptocti
    Created: 2026-07-31 13:17:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Malware #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RansomWare #bot #cryptocti

  7. Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor

    Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.

    Pulse ID: 6a693ba0eaf729fe7f4805da
    Pulse Link: otx.alienvault.com/pulse/6a693
    Pulse Author: cryptocti
    Created: 2026-07-28 23:30:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti

  8. 📣⚠️📞 Beware: Attackers posing as IT support staff are using Microsoft Teams and Quick Assist to access employee computers and install a new backdoor called #GoGRPC in attacks suspected of supporting ransomware operations.

    Listen/Read: hackread.com/fake-it-calls-mic

    #CyberSecurity #Backdoor #Malware #MicrosoftTeams #Vishing #Scam

  9. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

    Pulse ID: 6a678b1bffd8195d4d34ef68
    Pulse Link: otx.alienvault.com/pulse/6a678
    Pulse Author: AlienVault
    Created: 2026-07-27 16:45:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault

  10. Email bombing, finto IT support e un’estensione Edge che evade la sandbox: la tradecraft di UNC6692

    eSentire TRU ricostruisce la catena d'attacco dell'initial access broker UNC6692: email bombing, impersonificazione IT su Microsoft Teams, Quick Assist e l'estensione malevola Edgecution, capace di evadere la sandbox del browser per conto della syndicate ransomware Payouts King.

    insicurezzadigitale.com/email-

  11. Große Störung bei Microsoft: Der Dienst #MicrosoftTeams kämpft weltweit mit massiven Ausfällen. Meetings brechen ab oder starten erst gar nicht. Die Ursache ist noch unklar. #Teams winfuture.de/news,160172.html?

  12. Has an internal company Teams meeting planned all about Major/Crisis incidents and communication.

    Microsoft Teams in Australia decides to have a massive outage right on time.

    #Microsoft #Microsoft365 #MicrosoftTeams

  13. Email threat landscape: Q2 2026 trends and insights

    During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end.

    Pulse ID: 6a6241aa79fc3235d84045f9
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #CAPTCHA #CyberSecurity #Email #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #Phishing #bot #AlienVault

  14. 👨🏻‍💻 Du hast sicher schon mal an einer Online-Besprechung teilgenommen. Aber kannst Du so ein Teams-Meeting auch selbst planen und durchführen?
    malter365.de/teams/besprechung/

    #MicrosoftTeams #MSTeams #Teams

  15. [Edit: Falscher Alarm, Microsoft ist unschuldig. Tatsächlich stammt das Bild doch von der Seite: es ist dort zwar nicht zu sehen, aber im Quelltext als Teaserbild für Social Media angegeben. Sorry dass ich das nicht erst prüfte!]

    Was sollte eine Chat-Software tun, wenn für eine Linkvorschau kein Bild auf der Webseite gefunden werden kann? Richtig, natürlich selbst ein Bild generieren.

    MS Teams macht das genau richtig. Sarkasmus Ende.

    #Microsoft #AI_Slop #MicrosoftTeams #Dreckstool

  16. Schwarze Fenster bei der Bildschirmfreigabe: #MicrosoftTeams plagt derzeit Mac-Nutzer. Abhilfe schaffen ein aktuelles Update oder eine clevere Einstellung in den Optionen. #macOS winfuture.de/news,159925.html?