Attacks via Microsoft Teams – from Black Basta? 

B2B Cyber ​​Security ShortNews
Advertising

Share post

ReliaQuest experts have discovered a broader trend: a campaign using escalated social engineering tactics in Microsoft Teams, originally associated with the Black Basta ransomware group.

The previous approach was to bombard users with email spam and convince them to create a legitimate help desk ticket to resolve the issue. The attacker would then contact the end user or employee, posing as the help desk, to respond to the ticket.

Advertising
Perfect SME cybersecurity
How small and medium-sized enterprises defend against AI-led attacks with tailored security

Teams attacks via QR codes

In more recent incidents, attackers have refined their tactics by using Microsoft Teams chat messages to communicate with targeted users and embedding malicious QR codes to facilitate initial access. The nasty social engineering techniques are designed to trick users into downloading remote monitoring and management (RMM) tools, which the attackers can then use to gain access to the targeted environment. Ransomware is then likely to land on the system.

This rapidly escalating campaign poses a significant threat to organizations. The threat group is targeting many different industries and geographies with alarming intensity. The sheer volume of activity is also unique; in one incident, we observed approximately 50 emails bombarding a single user in just 1.000 minutes. Due to similarities in domain creation and Cobalt Strike configurations, it is highly likely that Black Basta is behind this activity.

Advertising

Attackers are still variable

During incidents in late October 2024, ReliaQuest experts observed several changes in Black Basta's tactics, techniques, and procedures (TTPs):

  • Following mass email spam events, the targeted users were added to Microsoft Teams chats with external users. These external users operated from Entra ID tenants they had created to impersonate support, administrator, or help desk staff.
  • In recent incidents, threat actors were observed tricking targeted users into using QuickAssist rather than just AnyDesk for “support” sessions. Additionally, in these chats, targeted users were sent QR codes posing as legitimate corporate QR code images.
More at ReliaQuest.com

 


About ReliaQuest 

ReliaQuest is here to make security possible. It enables security teams to detect, contain, and respond to threats in minutes - anytime, anywhere. Our GreyMatter platform enables enterprise security teams to leverage their current or future technology stack to achieve greater visibility and automation without the need to centralize data or standardize tools.


 

Matching articles on the topic

LockBit leak site hacked and data stolen

Now LockBit has also become the victim of another hacker: It seems that not only the leak page of the group was hacked, but ➡ Read more

F5 BIG-IP: BSI warns of highly dangerous vulnerabilities

The BSI has issued a warning about F5 products, as they contain several highly dangerous security vulnerabilities that should be closed. The BIG-IP ➡ Read more

Iran, North Korea, Russia: State hackers rely on ClickFix 

State-sponsored hacker groups are increasingly adopting new social engineering techniques originally developed by commercially motivated cybercriminals. ClickFix, for example, is now increasingly ➡ Read more

TA4557: Venom Spider targets HR departments

TA4557, better known as Venom Spider, is increasingly exploiting phishing and trying to deploy its backdoor malware. The focus of the ➡ Read more

Oettinger Brewery attacked by ransomware

The APT group Ransomhouse claims to have successfully attacked the German brewery Oettinger with ransomware. On the APT group's leak page ➡ Read more

Healthcare facilities: 90 percent are at high risk

The current report “State of CPS Security: Healthcare Exposures 2025” shows the most dangerous vulnerabilities of medical devices in networks of ➡ Read more

Google Cloud Run: ImageRunner vulnerability discovered

The ImageRunner privilege escalation vulnerability in Google Cloud Run could have allowed attackers to bypass access controls, gain unauthorized access to container images ➡ Read more

North Korean IT workers threaten European companies

The Google Threat Intelligence Group (GTIG) has published its latest findings on the activities of North Korean IT employees in Europe. These IT employees ➡ Read more