Microsoft Teams phishing targets employees with A0Backdoor malware

2026-03-10T07:23:30Zb83f6d2a60293cd51bbc4ef5f9d445386967f1e291176fb87c3d25e626238057
a0backdooraccount-hijackingarpa-dnscastleratcloud-exploitationdata-breachdonutloaderericsson-breachexperience-cloudipv6microsoft-teamsphishingphishing-evasionquick-assistremote-accessrussian-state-actorssalesforceshinyhunterssignalsupply-chaintermite-ransomwaretriZetto-healthcare-breachvelvet-tempestwhatsappzero-day-exploitation

What happened

Multiple active threat trends and breaches were reported: phishing via Microsoft Teams lures employees into granting remote access (Quick Assist) to deploy a new A0Backdoor; attackers increasingly exploit newly disclosed third‑party vulnerabilities to gain cloud access; Russian-linked actors are hijacking Signal and WhatsApp accounts of officials; and a service‑provider compromise led to a data theft at Ericsson US. Other incidents include ShinyHunters claiming Salesforce Experience Cloud data theft, Termite/Velvet Tempest using ClickFix to deliver DonutLoader and CastleRAT and enable Termite/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b83f6d2a60293cd51bbc4ef5f9d445386967f1e291176fb87c3d25e626238057
Enrichment time
2026-03-10T07:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.