Sunday, 27 Jul 2025
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • 🔥
  • Technology
  • World
  • Finance
  • Politics
  • Travel
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

Hackers hijack Microsoft Teams to spread malware to certain firms – find out if you’re at risk

Nexpressdaily
Last updated: July 17, 2025 11:46 am
Nexpressdaily
Share
SHARE


  • Researchers from Morphisec spotted Matanbuchus 3.0 in the wild
  • The malware serves as a loader for Cobalt Strike or ransomware
  • The victims are approached via Teams and asked for remote acccess

Security researchers are warning about an ongoing campaign leveraging Microsoft Teams calls to deploy a piece of malware called Matanbuchus 3.0.

As per cybersec outfit Morphisec, an unidentified hacking group first carefully picks its victims, and then reaches out via Microsoft Teams, posing as an external IT team.

They try to persuade the victim that they have a problem with their device and that they need to grant remote access in order to fix the issue. Since the victims are cherry-picked, there is a higher chance of success.


You may like

Expensive malware-as-a-service

Once the access is granted, usually through Quick Assist, the attackers execute a PowerShell script that deploys Matanbuchus 3.0, a malware loader that can lead to Cobalt Strike beacons, or even ransomware.

“Victims are carefully targeted and persuaded to execute a script that triggers the download of an archive,” Morphisec CTO Michael Gorelik said. “This archive contains a renamed Notepad++ updater (GUP), a slightly modified configuration XML file, and a malicious side-loaded DLL representing the Matanbuchus loader.”

This malware was first spotted in 2021, The Hacker News reports, where cybercriminals advertised it on Russian-speaking forums for $2,500. Since then, the malware has evolved to include new features, better communication, more stealth, CMD and PowerShell support, and more. It also apparently costs more, now having a monthly service price of $10,000 for the HTTPS version and $15,000 for the DNS version.

While the researchers do not identify the attackers, they did say that similar social engineering tactics were used in the past by a group called Black Basta to deploy ransomware.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

In the past, Black Basta was one of the most dangerous ransomware operations in existence, but has since then slowly phased out. In late February this year, a cybercriminal released chat logs that detailed the inner workings of the group.

Via The Hacker News

You might also like

Share This Article
Email Copy Link Print
Previous Article These Free People Hiking Pants Are Comfy and Packable
Next Article Got $5,000? 3 Top Growth Stocks to Buy That Could Double Your Money

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

California lawmaker behind SB 1047 reignites push for mandated AI safety reports

California State Senator Scott Wiener on Wednesday introduced new amendments to his latest bill, SB…

By Nexpressdaily

‘Something a bit naughty’: British snackers fall for the posh crisp | Snacks

When it comes to crisps, British appetites have traditionally been sated by a packet of…

By Nexpressdaily

ICE arrests Mexican boxer Julio César Chávez Jr., alleges cartel links

United States immigration agents have detained prominent Mexican boxer Julio César Chávez Jr. and are…

By Nexpressdaily

You Might Also Like

Technology

A Windows 11 bug is asking users to eject their GPU. Don’t do it!

By Nexpressdaily
Technology

While AI hasn't yet led to new physics discoveries, the tech is proving powerful in the field, aiding in experiment design and spotting patterns in complex data (Anil Ananthaswamy/Quanta Magazine)

By Nexpressdaily
Technology

The Polestar 4 now comes from South Korea instead of China

By Nexpressdaily
Technology

My favorite Shokz open-ear headphones are $60 off

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?