Microsoft Teams warns of another dangerous phishing attack spreading ransomware

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
(Image credit: weerapatkiatdumrong / Getty Images)

Microsoft has released a warning message to its Teams video conferencing customers amid ongoing attacks by a threat actor being tracked as Storm-0324, whereby phishing attacks lead to some pretty dangerous consequences.

Redmond’s researchers reveal that the group has been active since at least 2016, which means that over the course of around seven years, we have been able to draw some similarities between the group’s attacks.

The company says Storm-0324’s emails typically follow invoice and payment themes, mimicking services like DocuSign and Quickbooks. Microsoft itself has not been immune from attacks, as demonstrated in the latest Teams-focused attacks.

Another Teams phishing email

Analysts reckon that the group is abusing a Python program called TeamsPhisher, which was designed to let tenant users of the video conferencing software attach files to messages sent to external tenants.

Microsoft is most concerned about the ransomware attacks facilitated by the group’s phishing campaigns, stating that identifying and remediating Storm-0324’s activity is an important step in preventing “dangerous follow-on attacks.”

While the tech giant promises to be doing everything it can to eliminate such attacks, it advises that administrators can limit potentially destructive impacts by using the principle of least privilege, building credential hygiene, and following other company recommendations, even if attackers manage to gain initial access.

Microsoft Threat Intelligence has outlined several steps that companies and admins can take to protect themselves from these types of attacks in the supporting announcement.

The unfortunate reality is that some of the most sophisticated campaigns can catch even the most tech-savvy off guard, but there are some general pieces of advice that all consumers can follow in the face of rising cyber threats, including paying close attention to email details like the domain and address, and the grammar and layout of the content.

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
Microsoft Teams
Microsoft Teams is finally introducing a spam and phishing alert - here’s what you need to know
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC