Watch out – this fake Microsoft Teams app is actually dangerous malware, here’s how to stay protected



  • Attackers use compromised GMX Mail accounts to send fake Microsoft Teams invites with OAuth traps
  • Victims who authorize the malicious Azure Web App grant access to email, files, and persistent account control
  • Abnormal AI urges vigilance: verify senders, inspect links, and beware urgent meeting requests

Fraudsters are sending victims fake Microsoft Teams meeting invitations in a bid to steal ogin credentials and achieve persistent access across the Microsoft 365 ecosystem, experts have warned.

Cybersecurity experts from Abnormal AI said they recently observed the campaign in the wild. It starts with a compromised GMX Mail account. This is a free consumer email service from Germany which allows users to create up to ten sender addresses from a single account.


https://cdn.mos.cms.futurecdn.net/krBVBETP6cmxBcihGXQFy8-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img