HomeSecurityBlack Basta abuses Teams Chat to spread malware

Black Basta abuses Teams Chat to spread malware

The notorious Black Basta ransomware group has been observed exploiting Microsoft Teams as part of a sophisticated social engineering to spread malware.

See also: New malware technique exploits Windows UIA

Black Basta malware

This new tactic, which combines email bombing with the impersonation of IT support staff, has raised alarm in the cybersecurity.

The attack begins with a flood of spam emails hitting the target's inbox, inundating them with seemingly benign messages, such as newsletter subscriptions and account confirmations. This email deluge serves as a cover for the real threat that follows.

Once the victim's inbox is flooded, Black Basta attackers initiate contact via Microsoft Teams, posing as IT support staff offering assistance with the sudden influx of emails due to the malware.

See also: ZLoader malware uses DNS Tunneling technique

Threat actors create legitimate Microsoft Teams accounts using domains that mimic IT support services, such as:

  • securityadminhelper.onmicrosoft[.]com
  • supportserviceadmin.onmicrosoft[.]com
  • supportadministrator.onmicrosoft[.]com
  • cybersecurityadmin.onmicrosoft[.]com
Black Basta abuses Teams Chat to spread malware

These carefully constructed personas lend credibility to the attackers' claims, making it more likely for victims to trust and engage with them.

Black Basta operatives use sophisticated social engineering techniques to manipulate their targets. They create a sense of urgency around the issue of email bombing and offer a seemingly helpful solution, the NVISO Labs report states

The attackers then convince the victim to grant remote access to their system, usually through legitimate remote desktop tools like AnyDesk, TeamViewer, or Microsoft's Quick Assist.

See also: New Meeten malware targets macOS and Windows users

A malware campaign, such as that of Black Basta, refers to a coordinated effort by cybercriminals to distribute malicious software to unsuspecting users. These campaigns often use phishing, malicious websites, or software updates as delivery mechanisms. Once malware infects a system, it can perform a range of harmful activities, such as stealing sensitive data, encrypting files for ransom, or creating backdoors for continued access. Understanding and recognizing the signs of a malware campaign is crucial for both individuals and organizations in order to protect their digital assets and maintain cybersecurity .

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS