Microsoft Teams Used by Russia-Linked Hackers to Target Firms With Phishing Campaign, Microsoft Says

Microsoft has warned that the hackers have conducted "highly targeted" social engineering attacks on "fewer than 40 unique global organisations" since late May.

Advertisement
By Reuters | Updated: 3 August 2023 12:08 IST
Highlights
  • Teams is Microsoft's proprietary business communication platform
  • It has more than 280 million active users
  • The hackers used already-compromised Microsoft 365 accounts

Microsoft has mitigated the actor from using the domains

Photo Credit: Reuters

A Russian government-linked hacking group took aim at dozens of global organizations with a campaign to steal login credentials by engaging users in Microsoft Teams chats pretending to be from technical support, Microsoft researchers said on Wednesday.

These "highly targeted" social engineering attacks have affected "fewer than 40 unique global organizations" since late May, Microsoft researchers said in a blog, adding that the company was investigating.

The Russian embassy in Washington didn't immediately respond to a request for comment.

Advertisement

The hackers set up domains and accounts that looked like technical support and tried to engage Teams users in chats and get them to approve multifactor authentication (MFA) prompts, the researchers said.

Advertisement

"Microsoft has mitigated the actor from using the domains and continues to investigate this activity and work to remediate the impact of the attack," they added.

Teams is Microsoft's proprietary business communication platform, with more than 280 million active users, according to the company's January financial statement.

Advertisement

MFAs are a widely recommended security measure aimed at preventing hacking or stealing of credentials. The Teams targeting suggests hackers are finding new ways to get past it.

The hacking group behind this activity, known in the industry as Midnight Blizzard or APT29, is based in Russia, and the UK and US governments have linked it to the country's foreign intelligence service, the researchers said.

Advertisement

"The organizations targeted in this activity likely indicate specific espionage objectives by Midnight Blizzard directed at the government, non-government organizations (NGOs), IT services, technology, discrete manufacturing, and media sectors," they said, without naming any of the targets.

"This latest attack, combined with past activity, further demonstrates Midnight Blizzard's ongoing execution of their objectives using both new and common techniques," the researchers wrote.

Midnight Blizzard has been known to target such organizations, mainly in the US and Europe, going back to 2018, they added.

The hackers used already-compromised Microsoft 365 accounts owned by small businesses to make new domains that appeared to be technical support entities and had the word "Microsoft" in them, according to details in the Microsoft blog. Accounts tied to these domains then sent phishing messages to bait people via Teams, the researchers said. 

© Thomson Reuters 2023  


Samsung launched the Galaxy Z Fold 5 and Galaxy Z Flip 5 alongside the Galaxy Tab S9 series and Galaxy Watch 6 series at its first Galaxy Unpacked event in South Korea. We discuss the company's new devices and more on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, Hackers
Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  2. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  3. Sony's Year-End Holiday Sale on PS5 Accessories, Games Kicks Off Next Week
  4. Here's How Much The Redmi Note 15 5G Could Cost in India
  5. Here's When the Realme 16 Pro Series Will Launch in India
  6. This WhatsApp 'GhostPairing' Attack Lets Hackers Take Over Your Account
  7. YouTube Bans Popular Channels for Making Misleading AI-Generated Movie Trailers
  8. Honor Magic V6 Specifications Leaked; Might Launch With This Chip, Battery
  9. Oppo Reno 15 Pro Mini Tipped to Launch as First Compact Reno Smartphone
  10. Hubble spots a rare space collision near a nearby star
  1. Astronomers Observe Black Hole Twisting Spacetime for the First Time, Confirming Einstein’s Theory
  2. Hubble Captures Rare Collision in Nearby Planetary System, Revealing Violent Planet Formation
  3. Scientists Rule Out Elusive Sterile Neutrino After 10-Year Hunt, Shaking Particle Physics
  4. NASA’s PUNCH Mission Provides First Continuous Views of Solar Eruptions Across Space
  5. Starlink Satellite Breaks Apart in Orbit, Begins Uncontrolled Fall Toward Earth After SpaceX Anomaly
  6. Four More Shots Please Final Season Out on Prime Video: Know Everything About This Show For One Last Time
  7. Godday Godday Chaa 2 Now Streaming Online: A Powerful Punjabi Comedy with Social Satire
  8. Pharma Streaming Now on JioHotstar: Everything You Need to Know About This Thought-Provoking Drama Online
  9. Mrs. Deshpande Now Streaming Online: A Powerful Drama Exploring Identity, Marriage and Strength
  10. Adobe Partners With Runway to Offer Firefly Users Early Access to Video Generation Models
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.