Microsoft Teams phishing targets employees with A0Backdoor malware
2026-03-10T01:23:30Z•37696065a419f90ff08b3e5545e67187f0bcf1a8047cff3077b6fd500549cb0c
.arpaA0BackdoorCastleRATClickFixDonutLoaderEricssonIPv6Microsoft TeamsQuick AssistRussian state-sponsoredSalesforce AuraShinyHuntersSignalTermiteVelvet TempestWhatsAppaccount hijackingcloud exploitationdata breachphishingphishing-evasion`,`CISA`,`iOS`,`Coruna exploit kit`,`Cognizant-Transomwareservice-provider compromisevulnerability exploitationzero-day
What happened
Multiple high-impact cyber incidents and trends reported: Microsoft Teams used in targeted phishing to deploy a new A0Backdoor via Quick Assist; attackers increasingly exploit newly disclosed third‑party and cloud software flaws (shortening the window between disclosure and exploitation); Russian state-linked campaigns are hijacking Signal/WhatsApp accounts of officials; Ericsson US disclosed a service‑provider–related data breach; ShinyHunters claim Salesforce Aura data‑theft activity; Termite/Velvet Tempest ransomware activity leverages ClickFix to deliver DonutLoader and CastleRAT; threat-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 37696065a419f90ff08b3e5545e67187f0bcf1a8047cff3077b6fd500549cb0c
- Enrichment time
- 2026-03-10T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.