A sophisticated phishing campaign is targeting employees in the financial and healthcare sectors by impersonating IT support on Microsoft Teams to deploy a new malware called A0Backdoor.
Attack Method
- Email Bombing: Attackers first flood a victim’s inbox with thousands of spam emails to create distress and a sense of urgency.
- Teams Impersonation: A threat actor, posing as “Help Desk Manager” or similar IT staff, contacts the employee via Teams to offer help with the “spam issue.”
- Quick Assist Abuse: The attacker tricks the employee into starting a Microsoft Quick Assistsession, granting the hacker full remote control of the device.
- Malware Deployment: Once access is gained, they deploy A0Backdoor using digitally signed MSI installers hosted on legitimate Microsoft cloud storage to bypass security filters.
Key Technical Details of A0Backdoor
- Evasion: The malware uses anti-sandbox techniques, time-based execution, and runtime decryption to avoid detection by antivirus software.
- Stealth Communication: It uses covert DNS tunneling (via mail exchange records) to communicate with its command-and-control server without triggering network alarms.
- Threat Actor: Security researchers have linked this activity to the group Blitz Brigantine (also known as Storm-1811 or STAC5777), who are known affiliates of the Black Basta ransomwaregroup.
Recommended Protections
Control Quick Assist: Block or restrict the use of Quick Assist for standard users to prevent unauthorized remote sessions.
Verify Support: Always confirm IT support requests through an official, secondary company channel before granting remote access.
Restrict Teams Access: Organizations should configure Microsoft Teams to restrict chats from external domains and guest accounts.