Watch out – this devious Microsoft Teams phishing campaign could infect your PC

Teams
(Image credit: Microsoft)

Experts have warned Microsoft Teams messages are being used as a vector for a new phishing campaign designed to dupe users into downloading an attachment containing malware.

The malicious messages have been detected being sent from several compromised Office 365 accounts containing a ZIP file called "changes to the vacation schedule."

Clicking on this will download the file from a SharePoint URL. Inside the compressed file is what looks like a PDF file, but is actually a LNK file which itself contains dangerous VBScript that leads to the malware, known as DarkGate, being installed.

DarkGate

Cybersecurity firm Truesec launched an investigation into the phishing campaign and found that the download makes use of Windows cURL to fetch the malware's code, with the script being pre-compiled and the dangerous elements hidden in the middle of the file, in order to evade detection.

The script also checks to see whether popular antivirus solution Sophos is installed on the victim's endpoint. If it isn't, then additional code is unmasked and shellcode is launched to trigger the DarkGate executable and load it into the system memory. 

This is not the first time Microsoft Teams messages have been a cause for concern. Recently, a bug was found which allowed messages from external accounts to be received into an organization's inbox, which is not supposed to happen. It looks as if this new DarkGate campaign is making use of this flaw. 

Microsoft has not addressed the flaw directly; all it has done is recommend that organizations make allow-lists in Teams so that only certain external organizations can communicate with them, or else disable external communications altogether.

DarkGate has been around since 2017, but its use has been restricted to only a handful of cybercriminals against specific targets. It is a powerful and all-encompassing tool, capable of stealing files, browser data, and clipboard contents, as well as cryptomining, keylogging and remote control of endpoints. 

More from TechRadar Pro

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Microsoft Teams
Microsoft Teams is finally introducing a spam and phishing alert - here’s what you need to know
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025