Threat actors target Microsoft Teams using group chat invites: Report

Threat actors are using Microsoft Teams group chat invites to spread malware capable of compromising the security of corporate networks

January 31, 2024 02:24 pm | Updated 02:24 pm IST

Threat actors are abusing Microsoft Teams group chat requests for phishing attacks.

Threat actors are abusing Microsoft Teams group chat requests for phishing attacks. | Photo Credit: AP

Threat actors are abusing Microsoft Teams group chat requests for phishing attacks in a bid to gain access to organisations’ where admins haven’t secured their tenants by disabling the External Access setting.

Attackers are using what appear to be compromised Teams user (or domain) to send thousands of group chat invites, a report from the Bleeping Computer said.

The invites are sent to targets, who are tricked into downloading a file using double extension named ‘Navigating Future Changes October 2023.pdf.msi,.

Once the malicious file is downloaded by the victim, it can reach out to its command-and-control servers, thereby granting access to the victim’s device.

(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)

Microsoft Teams has become an attractive target for threat actors due to its pool of 280 million monthly users.

Similar campaigns were observed last year when threat actors targeted Office 365 and Skype accounts.

Additionally, cyber criminals are also making use of initial access brokers -- threat actors specialising in infiltrating computer systems and networks -- to launch phishing attacks in a bid to gain access to corporate networks.

Organisations are advised to disable External Access in Microsoft Teams, unless absolutely necessary. Also, users should pay attention to invites and check the source of unsolicited messages.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.