Microsoft Teams abused in Russian email bombing ransomware campaign

Shutterstock.com / kanlaya wanon
(Image credit: Shutterstock)

  • Sophos' researchers said they saw two groups engaging in email bombing attacks
  • At least 15 organizations were targeted in the last three months
  • The goal is to steal sensitive data and deploy ransomware

At least two threat actor groups are running email bombing campaigns against numerous organizations in the west, trying to steal their data and deploy ransomware.

Cybersecurity researchers Sophox X-Ops have observed more than 15 such incidents in the past three months, with half occurring in the last two weeks, suggesting that the criminals are picking up pace.

Email bombing is not a new tactic. It revolves around “bombing” the victim with hundreds, if not thousands of emails in a very short timespan, before the attackers contact the victims pretending to be an IT admin or network support worker.

Russian hackers

The attackers reportedly reach out via Microsoft Teams, or similar online collaboration tools, and offer to solve the issue. If the victim takes the bait, the attackers would demand access to Quick Assist or Microsoft Teams screen sharing, to take control of their targets’ computers. Once they are granted access, the attackers would deploy ransomware, the researchers said.

While Sophos X-Ops did not attribute the attacks to specific groups with great confidence, it did say that it “uncovered links” between one of the threat actors and Fin7 - a known Russian financially-motivated hacking collective.

The second group is seemingly linked to Storm-1811, another financially motivated cybercriminal group. This collective is known for deploying Black Basta ransomware through sophisticated social engineering attacks, and were observed impersonating IT staff in the past.

For Sean Gallagher, principal threat researcher at Sophos, the key of the problem lies in the fact that Teams’ default configuration allows individuals outside an organization to chat with, or call, internal staff at a company.

“Since many companies use managed service providers for their IT support, receiving a Teams call from an unknown person that’s labeled as ‘Help Desk Manager’ may not ring alarm bells, especially if it’s combined with an overwhelming amount of spam email,” Gallagher said.

“As Sophos continues to see new MDR and IR cases associated with these tactics, we want companies using Microsoft 365 to be on high alert. They should check company-wide configurations, block outside account messages if possible, and block remote access tools and remote machine management tools not regularly used by their organizations.”

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Russian flag on a laptop
Hackers are using Russian domains to launch complex document-based phishing attacks
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)