Cyber Security News

Hackers Abusing Teams Chat For Remote Session & To Drop Black Basta Malware

In a concerning development, the notorious ransomware group Black Basta has been observed leveraging Microsoft Teams as part of a sophisticated social engineering campaign.

This new tactic, which combines email bombing with impersonation of IT support staff, has raised alarms in the cybersecurity community.

The Attack Chain

The attack begins with a flood of spam emails to the target’s inbox, overwhelming them with seemingly benign messages such as newsletter subscriptions and account confirmations.

This deluge of emails serves as a smokescreen for the real threat that follows.

Once the victim’s inbox is inundated, the attackers initiate contact through Microsoft Teams, posing as IT support personnel offering assistance with the sudden influx of emails.

The threat actors create legitimate Microsoft Teams accounts using domains that mimic IT support services, such as:

– securityadminhelper.onmicrosoft[.]com

– supportserviceadmin.onmicrosoft[.]com

– supportadministrator.onmicrosoft[.]com

– cybersecurityadmin.onmicrosoft[.]com

These carefully crafted personas lend credibility to the attackers’ claims, making it more likely for victims to trust and engage with them.

Social Engineering Tactics

The Black Basta operatives employ sophisticated social engineering techniques to manipulate their targets. They create a sense of urgency around the email bombing issue and offer a seemingly helpful solution.

The attackers then persuade the victim to grant remote access to their system, typically through legitimate remote desktop tools like AnyDesk, TeamViewer, or Microsoft’s Quick Assist.

Once remote access is established, the true nature of the attack unfolds. The cybercriminals deploy various malicious payloads, including:

1. SystemBC: A proxy malware disguised as anti-spam software

2. Cobalt Strike beacons: Used for lateral movement and command execution

3. Zbot and DarkGate: Tools for credential harvesting and data exfiltration

Ultimately, these actions pave the way for the deployment of the Black Basta ransomware, encrypting the victim’s files and demanding a ransom for their release.

Detection And Prevention

Organizations can implement several measures to detect and prevent these attacks:

1. Monitor for spikes in incoming emails per user, regardless of their classification as spam, phishing, or malware.

2. Look for suspicious keywords like “Help Desk” or “Support” in Microsoft Teams display names.

3. Hunt for unusual Remote Monitoring and Management (RMM) tool usage within the environment.

4. Implement strict policies for external communications in Microsoft Teams.

5. Educate employees on recognizing social engineering attempts, especially those leveraging trusted platforms like Microsoft Teams.

The Broader Threat Landscape

This campaign by Black Basta is part of a larger trend of cybercriminals exploiting collaboration tools for malicious purposes.

As more organizations rely on platforms like Microsoft Teams for daily operations, these tools become increasingly attractive targets for threat actors.

The sophistication of this attack underscores the evolving nature of cyber threats.

By combining email bombing, social engineering, and abuse of legitimate collaboration tools, Black Basta demonstrates the complex challenges facing modern cybersecurity efforts.

As this threat continues to evolve, organizations must remain vigilant and adaptive in their security strategies.

Regular security awareness training, robust email filtering, and careful monitoring of collaboration platforms are essential components of a comprehensive defense against these advanced social engineering tactics.

The Black Basta campaign serves as a stark reminder that even trusted communication channels can be weaponized by determined adversaries.

As such, a multi-layered approach to security, combining technological solutions with human awareness, remains the best defense against these sophisticated cyber threats.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago