HackMyIP
← Back to News
2026-09-03 The Hacker News

Weekly Threat Roundup: Teams Phishing, Ransomware, OAuth Traps

PhishingRansomwareThreat Intel

Microsoft has warned of a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support and help desk personnel. Attackers socially engineer employees into granting interactive remote sessions, then deploy RMM tools to download malicious MSI packages via PowerShell. These packages stage a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and C2 capabilities. The threat actors perform extensive Active Directory reconnaissance, capture periodic desktop screenshots, and pivot across enterprise networks via Windows Remote Management toward domain controllers and other high-value assets.

A coordinated vishing campaign tracked as Spring Ring has been abusing external Microsoft Teams accounts to masquerade as IT help desk staff, targeting more than 150 employees across at least 10 companies between January and April 2026. According to Palo Alto Networks Unit 42, some 26 distinct attacker identities behind the operation coerce victims into installing RMM tools or custom malware. In more advanced variants, attackers escalated from vishing calls to full NTLM relay attacks against organizational domain controllers, underscoring how identity-based attacks remain a critical weak point in enterprise defenses.

Sophos has published fresh analysis on The Gentlemen ransomware operation, tracked internally as Gold Sherwood, which had claimed 683 victims by the end of July 2026. Separately, researchers disclosed the compromise of roughly 5,000 Dropbox accounts and uncovered new OAuth-based attacks that trick users into granting access to malicious applications through convincing fake consent screens. Together, these campaigns illustrate how attackers continue to weaponize trusted platforms, authentication flows, and brand familiarity to gain footholds inside corporate environments. Defenders are reminded that a single misspelled domain or a single click on "Allow" can be enough.

Security teams can reduce exposure by validating suspicious domains with an SSL/TLS checker, investigating unfamiliar registrants through a WHOIS lookup, and identifying compromised corporate credentials with an email breach checker before attackers can weaponize them in credential-stuffing or NTLM relay operations.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →