In the past few years, Microsoft has been promoting its communication service Microsoft Teams. Especially for enterprise users, this communication software can achieve very good auxiliary effects in productivity aspects such as team collaboration and communication. Recently, security researchers have warned that some malicious actors are hacking into Microsoft Teams accounts to gain access to chat groups and deliver malicious executable files to participants in the conversations.

Hackers break into Microsoft Teams messaging software to spread malware
More than 270 million people are active on Microsoft Teams every month, and even though the platform does not have enough protections to protect users from malicious files, many people still have a high level of trust in it. Recently, researchers from Avanan, a subsidiary of security research unit Check Point, discovered that hackers began to smuggle executable files containing malicious programs into conversations on the Microsoft Teams communication platform.

These attacks began to appear in January, and Avanan detected thousands of attacks. Avanan researcher Carl Rogers said that based on the existing data, most of the attacks were found in corporate organizations in the Great Lakes region of the United States, especially local media. In addition, Avanan explained that malicious people will insert a “User Centric” executable file (exe file) containing a Trojan horse into the chat group to trick users into clicking to run it. You don’t even need to download it, as it will take action with just two clicks. Once executed, the malware writes data to the system registry and installs a DLL on the Windows computer, paving the way for future exploitation. In addition, this malicious program also collects detailed information about the operating system and its computer hardware, as well as computer security status such as operating system version and installed fixes.

The method by which a bad actor gained access to a Teams account remains unclear, but it is speculated that it may have involved phishing or a malicious partner group to steal email or Microsoft 365 credentials. Avanan researchers said that although this attack is very simple, it can be very effective, mainly because many users place too much trust in the files they receive through Teams. In addition, Teams allows people outside the enterprise to collaborate because it provides guest and external access functions. Since many people are not familiar with the Teams platform, many people will directly trust and agree to various requests from Teams, making it easy for malicious people to pretend to be other colleagues to gain everyone’s trust.

This problem is exacerbated by the lack of built-in Teams security protection and the inability of many email security solutions to protect Teams due to limitations in scanning malicious links and files. To protect against such attacks, Avanan recommends that users take the following steps:
• For complete protection, download all archives to a sandbox and check them for malicious content before opening them
• Deploy a robust suite of security measures to protect all company-wide communications, including Teams
• Encourage end users within the company to contact IT if they see unfamiliar profiles
Source: KOCPC Chinese