A flaw in Microsoft Teams makes it possible for external accounts to distribute malware
Security researchers have discovered a straightforward method to introduce malware to a Microsoft Teams-using organization, despite the application's limitations on files from outside sources.
Microsoft Teams, a communication and collaboration tool that is a part of the Microsoft 365 cloud-based services, has been embraced by businesses and has 280 million active users each month.
Attack Information
The attack works with Microsoft Teams that are configured by default, which allows communication with Microsoft Teams accounts that are located outside of the organization, sometimes known as "external tenants."
Even while this communication link would be adequate for phishing and social engineering assaults, the approach they discovered is more potent because it enables sending a malicious payload directly to a target's inbox. Client-side security measures are in place in Microsoft Teams to prevent file delivery from external tenant accounts.
Attack illustration where the sender pretends to be a member of the IT staff (Jumpsec)
By altering the internal and external recipient IDs in the POST request of a message, an attacker can get past the restriction and trick the system into treating an external user as an internal one.
When the payload is sent in this manner, it is actually housed on a Sharepoint domain, where the recipient downloads it. However, it displays as a file, not a link, in the target inbox. The method was tried out in the real world, and as part of a covert red team engagement, the researchers were able to effectively deliver a command and control payload into an organization's mailbox.
Install NPAV on your systems to ensure best-in-class security against malware and ransomware attacks. Use NPAV and join us on a mission to secure the cyber world.
- Other (42)
- Ransomware (123)
- Events and News (26)
- Features (44)
- Security (422)
- Tips (79)
- Google (22)
- Achievements (8)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (42)
- Malware Alerts (187)
- Cyber Attack (219)
- Data Backup (11)
- Data Breach (75)
- Phishing (138)
- Securty Tips (1)
- Browser Hijack (16)
- Adware (15)
- Email And Password (67)
- Android Security (55)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (70)
- Hacking (57)
- Social Media (7)
- vulnerability (53)
- Hacker (31)
- Spyware (8)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (3)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (5)
- IoT Security (1)
- Deals and Offers (1)
- Cloud Security (8)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (1)
- DMart (1)
- Payment Risk (4)
- Occasion (2)
- firewall (1)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (4)
- Impersonation phishing (1)
- DDoS (4)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)