A social-engineering campaign targeting employees at financial and healthcare organizations is abusing Microsoft Teams chats/calls to trick users into granting remote access via Windows Quick Assist, enabling deployment of a newly identified malware family dubbed A0Backdoor. The activity begins with email bombing (flooding inboxes with spam) followed by an attacker impersonating internal IT over Teams, offering help and then persuading the victim to start a Quick Assist session; the tradecraft overlaps with tactics previously attributed to Blitz Brigantine / Storm-1811, which Microsoft has linked to Black Basta-associated operations.
Post-access, the actor deploys digitally signed MSI installers masquerading as Teams-related components and CrossDeviceService (associated with Windows Phone Link), sometimes delivered via tokenized links from Microsoft personal cloud storage to appear trustworthy and hinder collection. BlueVoyant reported the installers drop files into user AppData paths that mimic legitimate Microsoft locations and use DLL sideloading (e.g., a malicious hostfxr.dll) to execute an in-memory loader that decrypts shellcode, performs sandbox checks, and ultimately extracts and runs A0Backdoor (using AES-encrypted payloads and a SHA-256-derived key), with anti-analysis behavior including excessive thread creation intended to disrupt debugging.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft reported that after gaining remote access, the operators conduct reconnaissance, use trusted signed applications for DLL sideloading, move laterally over WinRM toward high-value systems such as domain controllers, and exfiltrate targeted data with Rclone to external cloud storage. The company framed the activity as a human-operated intrusion chain centered on cross-tenant helpdesk impersonation and abuse of legitimate administrative workflows.
BlueVoyant reported that the activity overlaps with Black Basta-associated tactics and assessed with moderate-to-high confidence that it represents an evolution of that tradecraft after the group's apparent dissolution following leaked internal chat logs. The report also noted new elements including signed MSIs, the A0Backdoor payload, and DNS MX-based command-and-control.
After obtaining remote access, the attackers deliver digitally signed MSI installers disguised as Microsoft Teams components or the legitimate CrossDeviceService tool, then abuse DLL sideloading with Microsoft-signed binaries and a malicious hostfxr.dll loader. The loader decrypts and launches a newly identified memory-resident payload called A0Backdoor.
Since 2024, attackers have used a social-engineering playbook in which targets are flooded with spam emails and then contacted over Microsoft Teams by actors posing as internal IT staff, who persuade them to start a Windows Quick Assist remote session. The campaign has targeted employees in financial and healthcare organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.