Cyber Security News

Hackers Leveraging Teams Messages to Execute Malware on Windows Systems

A new sophisticated attack campaign where cybercriminals are exploiting Microsoft Teams to deliver malware and maintain persistent access to corporate networks.

The attacks, which represent an evolution in social engineering tactics, specifically target Windows systems through a novel technique that security experts are calling a significant threat to enterprise security.

In March 2025, ReliaQuest discovered a complex attack chain involving Microsoft Teams phishing that deploys a previously unseen persistence method called TypeLib hijacking.

The attackers pose as IT support personnel and send phishing messages to employees through Teams, exploiting the platform’s trusted status within organizations.

“The attacks kicked off with the adversary sending phishing messages to our customers’ employees via Microsoft Teams,” ReliaQuest said to Cyber Security News. “The attacker used the fraudulent Microsoft 365 tenant with the display name ‘Technical Support’ to pose as a member of IT staff”.

After establishing contact, the attackers convince victims to launch Windows’ built-in “Quick Assist” tool, enabling remote access to the victim’s system.

This approach reflects a broader trend observed throughout 2024 and early 2025, where legitimate tools are leveraged in over 60% of hands-on-keyboard incidents.

Novel Persistence Technique

What makes these attacks particularly concerning is the implementation of TypeLib hijacking, a persistence technique first theorized by security researchers but now observed in real-world attacks. This method involves manipulating the Windows Registry to redirect legitimate COM objects to malicious scripts hosted on external URLs.

Novel Attack technique

“If explorer.exe calls the LoadTypeLib() function and we hijacked the necessary registry keys for the moniker, the moniker will be instantiated inside explorer.exe and its code will be executed,” explained researchers who initially discovered the technique.

This allows attackers to maintain persistent access that automatically reactivates after the system restarts.

Security experts have linked these techniques to Storm-1811, a threat group known to deploy Black Basta ransomware. However, ReliaQuest notes that the attacks show evidence of evolution or possible fragmentation among threat actors previously associated with Black Basta1.

The campaigns demonstrate precise targeting, with attacks carefully timed between 2:00 p.m. and 3:00 p.m. local time when employees may be less vigilant. Attackers specifically target executive-level employees and have shown a pattern of focusing on employees with female-sounding names.

Microsoft has acknowledged a significant increase in Teams phishing attacks since April 2024, which have led to numerous endpoint-related security incidents. The default configuration of Microsoft Teams, which permits calls and chats from external domains, has become a key vulnerability exploited by threat actors.

Cybersecurity company Sophos has observed multiple threat actors adopting similar techniques, including groups potentially connected to FIN7.

To defend against these attacks, security experts recommend implementing strict controls on external communications in Microsoft Teams, enabling multi-factor authentication, and conducting regular user awareness training. Organizations should also harden Windows systems to prevent the execution of malicious code through TypeLib hijacking.

As remote work continues to be common practice, collaboration platforms like Microsoft Teams remain prime targets for attackers looking to bypass traditional email security measures and exploit employees’ trust in enterprise communication tools.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago