Microsoft says this new malware could bankrupt your business

cyber security
(Image credit: Pixabay)

Cybersecurity experts at Microsoft are warning Office users of an elaborate new malware campaign that involves fake subscriptions, and fraudulent call centers.

Researchers at Microsoft Security Intelligence (MSI), who are actively tracking the campaign dubbed BazaCall, warn that the eventual goal of the threat actors is to deploy ransomware.

“We're tracking an active BazaCall malware campaign leading to human-operated attacks and ransomware deployment,” MSI shared via its official Twitter account.

The team added that the campaign gets its name from the BazaLoader malware that it seeks to deploy.

Ongoing campaign

Unraveling the modus operandi of the attack, MSI notes that inspired by a traditional tech-support scam, the campaign first uses emails to lure recipients to ring up a number to cancel their supposed subscription to a particular service.

Engaging with the threat actors on the other side of the fraudulent call center, the unsuspecting user is then instructed to download an Excel file in order to cancel the service. MSI says that this Excel file contains a malicious macro that downloads the BazaLoader malware.

MSI says that while Microsoft 365 Defender is equipped to identify and defend against such spurious emails, it is the lack of any tell-tale malicious elements in the emails that is currently proving to be a challenge.

Even as they continue to study and understand the ongoing campaign in detail, the MSI team has shared advanced hunting queries to help IT and cybersecurity staff to identify signs of the campaign, including the fraudulent emails, in order to nip the attack in the bud itself. 

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
Magnifying glass enlarging the word 'malware' in computer machine code
Microsoft Teams and AnyDesk abused to deploy dangerous malware, so be on your guard
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
Illustration of a laptop with a magnifying glass exposing a beetle on-screen
Microsoft Outlook targeted by new malware attacks allowing sneaky hijacking
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection