Microsoft Teams warns of another dangerous phishing attack spreading ransomware
Microsoft has released a warning message to its Teams video conferencing customers amid ongoing attacks by a threat actor being tracked as Storm-0324, whereby phishing attacks lead to some pretty dangerous consequences.
Redmond’s researchers reveal that the group has been active since at least 2016, which means that over the course of around seven years, we have been able to draw some similarities between the group’s attacks.
The company says Storm-0324’s emails typically follow invoice and payment themes, mimicking services like DocuSign and Quickbooks. Microsoft itself has not been immune from attacks, as demonstrated in the latest Teams-focused attacks.
Another Teams phishing email
Analysts reckon that the group is abusing a Python program called TeamsPhisher, which was designed to let tenant users of the video conferencing software attach files to messages sent to external tenants.
Microsoft is most concerned about the ransomware attacks facilitated by the group’s phishing campaigns, stating that identifying and remediating Storm-0324’s activity is an important step in preventing “dangerous follow-on attacks.”
While the tech giant promises to be doing everything it can to eliminate such attacks, it advises that administrators can limit potentially destructive impacts by using the principle of least privilege, building credential hygiene, and following other company recommendations, even if attackers manage to gain initial access.
Microsoft Threat Intelligence has outlined several steps that companies and admins can take to protect themselves from these types of attacks in the supporting announcement.
The unfortunate reality is that some of the most sophisticated campaigns can catch even the most tech-savvy off guard, but there are some general pieces of advice that all consumers can follow in the face of rising cyber threats, including paying close attention to email details like the domain and address, and the grammar and layout of the content.
More from TechRadar Pro
Microsoft has released a warning message to its Teams video conferencing customers amid ongoing attacks by a threat actor being tracked as Storm-0324, whereby phishing attacks lead to some pretty dangerous consequences. Redmond’s researchers reveal that the group has been active since at least 2016, which means that over the…
Recent Posts
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023