Microsoft Teams phishing targets employees with A0Backdoor malware
2026-03-10T07:23:30Z•b83f6d2a60293cd51bbc4ef5f9d445386967f1e291176fb87c3d25e626238057
a0backdooraccount-hijackingarpa-dnscastleratcloud-exploitationdata-breachdonutloaderericsson-breachexperience-cloudipv6microsoft-teamsphishingphishing-evasionquick-assistremote-accessrussian-state-actorssalesforceshinyhunterssignalsupply-chaintermite-ransomwaretriZetto-healthcare-breachvelvet-tempestwhatsappzero-day-exploitation
What happened
Multiple active threat trends and breaches were reported: phishing via Microsoft Teams lures employees into granting remote access (Quick Assist) to deploy a new A0Backdoor; attackers increasingly exploit newly disclosed third‑party vulnerabilities to gain cloud access; Russian-linked actors are hijacking Signal and WhatsApp accounts of officials; and a service‑provider compromise led to a data theft at Ericsson US. Other incidents include ShinyHunters claiming Salesforce Experience Cloud data theft, Termite/Velvet Tempest using ClickFix to deliver DonutLoader and CastleRAT and enable Termite/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b83f6d2a60293cd51bbc4ef5f9d445386967f1e291176fb87c3d25e626238057
- Enrichment time
- 2026-03-10T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.