Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Trick Users into Download Weaponized Microsoft Teams to Gain Remote Access

A recent cyber campaign has been identified, exploiting the trust in popular collaboration software by tricking users into downloading a compromised version of Microsoft Teams. This version is designed to enable remote access to victims' systems.

A recent cyber campaign has been identified, exploiting the trust in popular collaboration software by tricking users into downloading a compromised version of Microsoft Teams. This version is designed to enable remote access to victims' systems.

Threat actors are employing search engine optimization (SEO) poisoning and malicious advertisements to redirect users to fraudulent download pages. This approach is similar to previous campaigns targeting other trusted software.

Blackpoint has reported that users searching for "Microsoft Teams download" are encountering malicious ads leading to spoofed websites. One such domain, teams-install[.]top , mimics the official Microsoft download portal, offering a malicious file named MSTeamsSetup.exe .

These installers often use dubious digital certificates from issuers such as "4th State Oy" and "NRM NETWORK RISK MANAGEMENT INC." to bypass basic security checks that flag unsigned software.

Weaponized Microsoft Teams Delivers Oyster Backdoor

Executing the rogue installer initiates a multi-stage attack, deploying a persistent backdoor known as Oyster or Broomstick.

Threat actors are employing search engine optimization (SEO) poisoning and malicious advertisements to redirect users to fraudulent download pages.
Carter Hartwell · Thehackingpost

The malware installs a malicious DLL file named CaptureService.dll in the %APPDATA%\Roaming folder and creates a scheduled task, CaptureService , to maintain persistence. This task ensures the backdoor remains active even after a system reboot, camouflaging it within normal Windows activity.

The Oyster backdoor facilitates remote access, system information collection, and communication with command-and-control (C2) servers, allowing data exfiltration and receipt of additional instructions or payloads.

In this campaign, Oyster has been observed connecting to C2 domains such as nickbush24[.]com and techwisenetwork[.]com, as revealed by Blackpoint analysis. The campaign is part of a broader trend of cybercriminals exploiting well-known software brands for initial access. Similar tactics have been used in previous campaigns distributing fake installers for PuTTY , WinSCP, and Google Chrome.

Leveraging malvertising and SEO poisoning, attackers can target a wide audience, exploiting user trust in both search engines and popular enterprise tools. The use of the Oyster backdoor is particularly concerning, as it has ties to ransomware operations like Rhysida, which utilize it to infiltrate corporate networks.

Advertisement

This strategy indicates a shift where threat actors are not solely relying on phishing emails but are also compromising the software supply chain at the user-download level. The campaign is designed to bypass some traditional antivirus and endpoint detection and response EDR solutions , posing a stealthy and significant threat.

To mitigate this risk, organizations and individuals are advised to download software exclusively from official vendor websites. Using saved bookmarks for frequently accessed download pages is recommended over relying on search engine results, especially sponsored advertisements. Vigilance and user education are crucial defenses against these evolving social engineering tactics.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories