HomeSecurityAbuse of Microsoft Teams and Quick Assist to distribute A0Backdoor

Abuse of Microsoft Teams and Quick Assist to distribute the A0Backdoor

A new and highly sophisticated cyber campaign has come to light, with experts identifying a previously unknown malware called A0Backdoor . The malware appears as part of a targeted operation social engineering that exploits Microsoft tools, such as Microsoft Teams and the built-in Windows Quick Assist remote support tool .

Microsoft Teams and Quick Assist A0Backdoor

The group behind the campaign is being tracked by researchers under various names, including Blitz Brigantine, Storm-1811 , and STAC5777, and is said to have connections to the ransomware Black Basta. According to analysis, the group's activity can be traced back to at least August 2025 and continues into early 2026, with key targets in the financial services and healthcare sectors.

How the attack starts: Spam, confusion and fake IT support

The method used by the attackers is based on a combination of social engineering and system compromise techniques. The first stage of the attack begins with a mass mailing of spam emails to the target. Thousands of emails flood the victim's inbox, creating an environment of confusion and pressure.

See also: DRILLAPP Backdoor targets Ukraine with Microsoft Edge debugging

Immediately afterwards, the perpetrators contact the victim via Microsoft Teams, pretending to be members of the technical support team . Taking advantage of the panic they have already created, they offer help in resolving the spam email problem.

The next step is crucial: the attackers convince the victim to use Quick Assist, a Windows tool that allows a computer to be controlled remotely. Once the user grants access, the attackers gain complete control of the system.

Installation of malicious software disguised as a Microsoft application

With remote access enabled, attackers quickly install a malicious software package that looks like a legitimate Microsoft application. Researchers at BlueVoyant found that these files appeared to be installations of Microsoft Teams or a utility called CrossDeviceService.

The packages were distributed as digitally signed MSI files, which made them look like genuine software updates. In fact, analysts identified at least three code signing certificates used as early as July 2025, indicating that the group had carefully developed its tool for months before launching the attack.

Abuse of Microsoft Teams and Quick Assist to distribute the A0Backdoor

The DLL sideloading technique behind A0Backdoor

The infection mechanism is based on a well-known but highly effective technique called DLL sideloading. When the malicious MSI is installed, the system loads a DLL file that is supposedly part of a legitimate application.

See also: ClickFix techniques used in new infostealer campaigns

In reality, attackers replace the hostfxr.dll, a .NET runtime component that is usually signed by Microsoft, with a malicious version. The forged file is digitally signed by a company called MULTIMEDIOS CORDILLERANOS SRL, making it appear trustworthy.

When the normal program runs, it loads the malicious DLL and thus the malware is activated without raising suspicion.

Advanced concealment and communication techniques

The malicious file decrypts hidden data within its own code and triggers a shellcode payload. To make it difficult for researchers to analyze, the loader executes a large number of CreateThread, which can cause errors in debugging tools.

The malware also checks whether it is running in a virtual environment or sandbox, looking for clues such as the QEMU. It also uses a decryption system with a key that changes approximately every 55 hours, making it very difficult to analyze outside of the correct time window.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

To communicate with its operators, A0Backdoor uses DNS tunneling, sending DNS MX requests through public resolvers such as 1.1.1.1. This method allows the malware to hide within normal network traffic.

Which organizations were targeted

According to the investigation, the victims included professionals at a financial institution in Canada as well as a global health organization. These attacks show that the perpetrators are targeting organizations with high-value data and significant access to sensitive information.

See also: GlassWorm: 72 malicious Open VSX extensions target developers

Abuse of Microsoft Teams and Quick Assist to distribute the A0Backdoor

How can organizations protect themselves?

Cybersecurity experts recommend a number of measures to prevent such attacks. One of the most important is to limit the use of Quick Assist in corporate environments and implement policies that block unauthorized remote access sessions.

Equally important is training employeesto always verify any IT support message they receive through platforms like Microsoft Teams.

Security teams are also urged to monitor for suspicious MSI files in AppData folders, detect outbound DNS MX queries to public resolvers, and check for DNS tunneling activities.

Finally, restricting external communication in Microsoft Teams from unknown organizations may remove one of the key channels this group of attackers uses for initial contact with their victims.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS