Recently, there have been rumors that the platform Microsoft Teams ransomware attacks. However, Microsoft has issued a statement denying these rumors and claiming that its platform has never been used by cybercriminals to carry out ransomware attacks on systems .
We don't know exactly how this rumor originated or who started it, but it came to light earlier this month when several companies across Spain were infected with the DoppelPaymer.
“Microsoft is investigating recent attacks by malicious hackers using the Dopplepaymer ransomware,” said Simon Pope, an executive at the Microsoft Security Response Center (MSRC).
Pope said that the information circulating that the Microsoft Teams platform is being used to spread malware is misleading.
“Our research teams have reviewed the attacks and found no evidence to support these claims,” he added. “In our investigations, we found that the malware relies on stolen credentials to spread across corporate networks.”
In addition to rumors about the involvement of the Microsoft Teams platform in ransomware attacks, Pope also spoke about some other rumors that are circulating mainly on social media.
According to these rumors, cybercriminals are using the BlueKeep RDP vulnerability to install the DoppelPaymer ransomware. These rumors are also related to the attacks in Spain.
This is the first time that Microsoft has taken the initiative to respond and make official statements denying the news circulating on the internet.

The news about Microsoft Teams was circulated on many sites, however, it could easily be refuted by the same people as well as by securitywho know something about the attacks.
To begin with, the DoppelPaymer ransomware is a variant of the BitPaymer. Experts know that this malware has been distributed exclusively via the Dridex botnet or the Emotet botnets.
Microsoft researchers said that these botnets are typically used by ransomware gangs to gain access to companies' internal networks. As Pope explained, hackers steal employee credentials, enter the company's internal network, and spread to other systems. Finally, they install DoppelPaymer.
Furthermore, in the attacks that exploited the BlueKeep, the ultimate goal was to install a cryptominer.
According to Microsoft, there has been no publicly documented case where BlueKeep was used to install ransomware.
As some researchers, most RDP attacks today are RDP brute-force attacks and do not rely on the BlueKeep exploit.
