Microsoft Teams phishing targets employees with A0Backdoor malware

2026-03-10T01:23:30Z37696065a419f90ff08b3e5545e67187f0bcf1a8047cff3077b6fd500549cb0c
.arpaA0BackdoorCastleRATClickFixDonutLoaderEricssonIPv6Microsoft TeamsQuick AssistRussian state-sponsoredSalesforce AuraShinyHuntersSignalTermiteVelvet TempestWhatsAppaccount hijackingcloud exploitationdata breachphishingphishing-evasion`,`CISA`,`iOS`,`Coruna exploit kit`,`Cognizant-Transomwareservice-provider compromisevulnerability exploitationzero-day

What happened

Multiple high-impact cyber incidents and trends reported: Microsoft Teams used in targeted phishing to deploy a new A0Backdoor via Quick Assist; attackers increasingly exploit newly disclosed third‑party and cloud software flaws (shortening the window between disclosure and exploitation); Russian state-linked campaigns are hijacking Signal/WhatsApp accounts of officials; Ericsson US disclosed a service‑provider–related data breach; ShinyHunters claim Salesforce Aura data‑theft activity; Termite/Velvet Tempest ransomware activity leverages ClickFix to deliver DonutLoader and CastleRAT; threat-­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
37696065a419f90ff08b3e5545e67187f0bcf1a8047cff3077b6fd500549cb0c
Enrichment time
2026-03-10T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.