financetom
Technology
financetom
/
Technology
/
Microsoft says Russian hackers behind dozens of Teams phishing attacks
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft says Russian hackers behind dozens of Teams phishing attacks
Aug 3, 2023 7:43 AM

A Russian government-linked hacking group took aim at dozens of global organisations with a campaign to steal login credentials by engaging users in Microsoft Teams chats pretending to be from technical support, Microsoft researchers said on Wednesday.

These "highly targeted" social engineering attacks have affected "fewer than 40 unique global organisations" since late May, Microsoft researchers said in a blog, adding that the company was investigating.

The Russian embassy in Washington didn't immediately respond to a request for comment.

The hackers set up domains and accounts that looked like technical support and tried to engage Teams users in chats and get them to approve multifactor authentication (MFA) prompts, the researchers said.

"Microsoft has mitigated the actor from using the domains and continues to investigate this activity and work to remediate the impact of the attack," they added.

Teams is Microsoft's proprietary business communication platform, with more than 280 million active users, according to the company's January financial statement.

MFAs are a widely recommended security measure aimed at preventing hacking or stealing of credentials. The Teams targeting suggests hackers are finding new ways to get past it.

The hacking group behind this activity, known in the industry as Midnight Blizzard or APT29, is based in Russia and the UK and US governments have linked it to the country's foreign intelligence service, the researchers said.

"The organisations targeted in this activity likely indicate specific espionage objectives by Midnight Blizzard directed at government, non-government organisations (NGOs), IT services, technology, discrete manufacturing, and media sectors," they said, without naming any of the targets.

"This latest attack, combined with past activity, further demonstrates Midnight Blizzard’s ongoing execution of their objectives using both new and common techniques," the researchers wrote.

Midnight Blizzard has been known to target such organisations, mainly in the US and Europe, going back to 2018, they added.

The hackers used already-compromised Microsoft 365 accounts owned by small businesses to make new domains that appeared to be technical support entities and had the word "microsoft" in them, according to details in the Microsoft blog. Accounts tied to these domains then sent phishing messages to bait people via Teams, the researchers said.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
BRIEF-Omdia Says Demand For Google's Tpu Chips Accelerates Challenging Nvidia's Dominance
BRIEF-Omdia Says Demand For Google's Tpu Chips Accelerates Challenging Nvidia's Dominance
Dec 18, 2024
Dec 18 (Reuters) - Omdia: * OMDIA: DEMAND FOR GOOGLE'S TPU CHIPS ACCELERATES CHALLENGING NVIDIA'S DOMINANCE Source text: Further company coverage: ...
Forecasting The Future: 11 Analyst Projections For Electronic Arts
Forecasting The Future: 11 Analyst Projections For Electronic Arts
Dec 18, 2024
Providing a diverse range of perspectives from bullish to bearish, 11 analysts have published ratings on Electronic Arts ( EA ) in the last three months. The following table summarizes their recent ratings, shedding light on the changing sentiments within the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings...
Expert Outlook: Q2 Holdings Through The Eyes Of 12 Analysts
Expert Outlook: Q2 Holdings Through The Eyes Of 12 Analysts
Dec 18, 2024
12 analysts have shared their evaluations of Q2 Holdings ( QTWO ) during the recent three months, expressing a mix of bullish and bearish perspectives. In the table below, you'll find a summary of their recent ratings, revealing the shifting sentiments over the past 30 days and comparing them to the previous months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish...
Analyst Expectations For BILL Holdings's Future
Analyst Expectations For BILL Holdings's Future
Dec 18, 2024
Across the recent three months, 12 analysts have shared their insights on BILL Holdings ( BILL ) , expressing a variety of opinions spanning from bullish to bearish. The table below provides a snapshot of their recent ratings, showcasing how sentiments have evolved over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat...
Copyright 2023-2025 - www.financetom.com All Rights Reserved