Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Using "holiday adjustment" as bait, experts found a new type of fishing activity for Microsoft Teams

Shulou Source: shulou.com Published: 2023-11-24 20:36:34 10月04日 Update

CTOnews.com Sept. 12, according to the latest report released by Truesec, a network security company, DarkGate Loader phishing activities aimed at Microsoft Teams users have been discovered.

The attacker first uses the leaked Office 365 account to send an email containing a malicious attachment to the user and marks the attachment as a ZIP file that "adjusts the holiday schedule".

After the user clicks on the ZIP file, the download process is automatically initiated from SharePoint URL, which contains the LNK file disguised as an PDF document.

It is reported that hackers hijacked "Akkaravit Tattamanas" (63090101@my.buu.ac.th) and "ABNER DAVID RIVERA ROJAS" (adriverar@unadvirtual.edu.co) accounts, hidden malicious VBScript in LNK files, and then deployed malware called DarkGate Loader.

Because SharePoint URL is used in the download process of ZIP files, the complex activities exploited by hackers make it difficult for users to detect violations. In addition, the code is hidden in the middle of the file, making it difficult for mainstream software killers to detect malware in precompiled scripts.

CTOnews.com attaches a link to the security report here, which interested users can click to read in depth.

Tags: File user malicious activity security report network account software process attachment hacker detection adjustment complexity two mainstream code company interest Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn Shulou Technology NVidia Shulou Tech Info Redmi