New A0Backdoor Malware Spread via Microsoft Teams Phishing
Mar 10, 2026 // 07:53 - Niko Dunn


A sophisticated phishing campaign is targeting employees in the financial and healthcare sectors by impersonating IT support on Microsoft Teams to deploy a new malware called A0Backdoor.

Attack Method

  • Email Bombing: Attackers first flood a victim’s inbox with thousands of spam emails to create distress and a sense of urgency.
  • Teams Impersonation: A threat actor, posing as “Help Desk Manager” or similar IT staff, contacts the employee via Teams to offer help with the “spam issue.”
  • Quick Assist Abuse: The attacker tricks the employee into starting a Microsoft Quick Assistsession, granting the hacker full remote control of the device.
  • Malware Deployment: Once access is gained, they deploy A0Backdoor using digitally signed MSI installers hosted on legitimate Microsoft cloud storage to bypass security filters.

Key Technical Details of A0Backdoor

  • Evasion: The malware uses anti-sandbox techniques, time-based execution, and runtime decryption to avoid detection by antivirus software.
  • Stealth Communication: It uses covert DNS tunneling (via mail exchange records) to communicate with its command-and-control server without triggering network alarms.
  • Threat Actor: Security researchers have linked this activity to the group Blitz Brigantine (also known as Storm-1811 or STAC5777), who are known affiliates of the Black Basta ransomwaregroup.

Recommended Protections

Control Quick Assist: Block or restrict the use of Quick Assist for standard users to prevent unauthorized remote sessions.

Verify Support: Always confirm IT support requests through an official, secondary company channel before granting remote access.

Restrict Teams Access: Organizations should configure Microsoft Teams to restrict chats from external domains and guest accounts.

#a0backdoor  #malware  #microsoft  #new  #news  #phishing  #spread  #teams  #via   —   News