Blog | G5 Cyber Security

Ransomware operators use fake Microsoft Teams updates to deploy Cobalt Strike

Ransomware operators use fake Microsoft Teams updates to deploy Cobalt Strike and compromise the target networks. Microsoft has issued a non-public security advisory issued by BleepingComputer warning its customers of malware campaigns using malware campaigns. The technique is not new and threat actors already exploited it in the wild. In one of the attacks spotted by Microsoft, threat actors were spreading a tainted copy of Microsoft Teams. Threat actors also distributed other malware, like the Bladabindi (NJRat) backdoor and Zloader info-stealer.”]

Source: https://securityaffairs.co/wordpress/110693/malware/fake-microsoft-teams-cobalt-strike.html

Exit mobile version