Attackers used email bombing and fake IT support messages over Microsoft Teams to trick employees into launching Windows Quick Assist, giving remote access that led to the deployment of Nimbus RAT. eSentire said the campaign targeted corporate organizations globally, with notable impact on the legal sector, and observed a full compromise path from Teams contact to RAT execution in under 20 minutes. In one documented intrusion, the victim received more than 280 legitimate subscription emails before being contacted by an actor-controlled Teams account, then was directed to download malware from a compromised Microsoft 365 tenant hosted on SharePoint.
Nimbus RAT is a Java-based backdoor bundled with OpenJDK to run on Windows systems and uses Google Drive and Google Sheets for command-and-control, helping malicious traffic blend into normal SaaS activity. Researchers said the malware supports command execution, file and registry manipulation, screenshot capture, in-memory payload execution, and credential theft, while a secondary tool, InboxSetupPro, uses OneDrive for exfiltration and steals communications data including Signal attachments and large offline email archives. eSentire reported 1,540 similar Teams-related events across 172 customer environments, with activity rising sharply from December 2025 through March 2026, prompting recommendations to restrict external Teams communications, disable Quick Assist where possible, monitor transfers to public cloud storage, and train users to spot email-flooding and fake helpdesk tactics.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In April 2026, attackers targeted a legal-sector organization with email bombing, fake IT support contact over Microsoft Teams, and Quick Assist social engineering to deploy Nimbus RAT from a compromised Microsoft 365 tenant.
eSentire’s Threat Response Unit identified a coordinated cyber espionage campaign using email bombing, Microsoft Teams vishing, Quick Assist, and compromised Microsoft 365 infrastructure to deliver Nimbus RAT and the InboxSetupPro data theft tool.
eSentire telemetry recorded 1,540 similar Microsoft Teams-related events across 172 customer environments between December 2025 and March 2026, indicating a broader campaign abusing Teams and related cloud services.
JUMPSEC’s Detection and Response Team identified a phishing campaign using Thai-language payment-slip lures, WinRAR self-extracting archives, and temporary network disruption to deploy Remcos RAT. Investigators attributed the cluster to BlackToad and linked it behaviorally to the SilverTerrier ecosystem and the BoredFluff campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.