< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybersecurity researchers warn of new Microsoft Teams and phishing attacks

Security researchers have identified evolving cyberattack methods targeting users through trusted platforms like Microsoft Teams.

BlueVoyant reported a new distribution method for the FireClient backdoor. Attackers use social engineering via Microsoft Teams to trick users into granting remote access through tools like Quick Assist. The infection chain utilizes Windows Installer (MSI) packages containing a portable version of the multimedia application Kodi. By employing DLL sideloading, a manipulated zlib.dll file is loaded to trigger the FireClient loader, which then communicates with command-and-control servers hosted on AWS API Gateway.

Separately, Barracuda Networks identified a novel phishing technique that bypasses traditional web filters by generating fake login pages using Blob URLs directly in the victim's browser memory. These attacks do not rely on external phishing websites, making them invisible to standard URL blocklists. The attackers leverage trusted Microsoft infrastructure and service workers to control browser interactions in real-time. Experts recommend moving toward phishing-resistant authentication, such as FIDO2 and passkeys, to mitigate these serverless threats.

Entities

AWS · Barracuda Networks · BlueVoyant · Kodi · Microsoft