Skip to main content
  1. Home
  2. Computing
  3. News

Hackers are sending malware through seemingly innocent Microsoft Teams messages

Add as a preferred source on Google

Hackers are getting so sophisticated with malware that they are making links look like a notice about company vacation time.

A new phishing scam called “DarkGate Loader” has been uncovered that targets Microsoft Teams. It can be identified with a message and a link that reads “changes to the vacation schedule.” Clicking this link and accessing the corresponding .ZIP files can leave you vulnerable to the malware that is attached.

Microsoft Team message showing DarkGate Loader malware.
Truesec Research

The research team Truesec has been observing DarkGate Loader since late August and notes that hackers have utilized an intricate downloading process that makes it so the file is difficult to identify as nefarious.

Recommended Videos

Hackers were able to use compromised Office 365 accounts to send the malware-infected message with the “changes to the vacation schedule” link through Microsoft Teams. Truesec found the accounts that were taken over by the hackers to send the DarkGate Loader malware. These include “Akkaravit Tattamanas” (63090101@my.buu.ac.th) and “ABNER DAVID RIVERA ROJAS” (adriverar@unadvirtual.edu.co).

The malware comprises an infected VBScript hidden within an LNK (a Windows shortcut). The research team notes that the attack is crafty due to its SharePoint URL, which makes it hard for users to realize it’s a challenged file. The precompiled Windows cURL script type also makes the code harder to identify because the code is hidden in the middle of the file.

The script is able to pinpoint if the user has the antivirus Sophos installed. If not, the malware can inject additional code, in an attack called “stacked strings,” which opens a shellcode that creates a DarkGate executable that loads into the system memory, the team added.

DarkGate Loader isn’t the only phishing scam that has been plaguing Microsoft Teams this summer. A group of Russian hackers called Midnight Blizzard were able to use a social engineering exploit to attack approximately 40 organizations in August. The hackers used Microsoft 365 accounts owned by small businesses that had already been challenged and pretended to be technical support in order to execute attacks. Microsoft has since addressed the issue, according to Windows Central.

Last fall, one common trend was business email compromise (BEC) campaigns, which are phishing scams where a nefarious actor, disguised as a company boss, sends an email that looks like a forwarded email chain, with instructions to an employee to send money.

Another infamous exploit was the Windows zero-day vulnerability Follina. Researchers discovered it in the spring of last year and determined it allowed hackers access to the Microsoft Support Diagnostic Tool that is commonly associated with Microsoft Office and Microsoft Word.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Gemini Notebook’s latest update makes it a better study companion
Google is adding voice conversations, lecture recording, interactive quizzes, and short video overviews to its AI-powered notebook.
Gemini Notebook update for students

Google is giving Gemini Notebook, formerly NotebookLM, a major upgrade for students, adding new features designed to help them understand difficult concepts, capture lectures, and turn study materials into interactive learning tools. The update lands alongside a free year of Google's paid AI plan for eligible college students.

Gemini Notebook can now talk you through your notes

Read more
LG 39GX950B review: An ultrawide OLED that gets remarkably close to having it all
LG’s 39-inch 5K2K OLED combines high-end picture quality with seriously fast gaming
Electronics, Screen, Computer Hardware

see at bestbuy

Quick Verdict

Read more
Should we feel bad about deleting an AI? One expert says it’s time to find out
If AI can learn, remember, and make increasingly complex decisions, one expert thinks we should be more careful about how we say goodbye.
an on off toggle

Turning off an AI might sound as simple as hitting a switch, but according to futurist and University of Technology Sydney professor Rocky Scopelliti, that mindset needs to change fast. As first reported by TechXplore, Scopelliti's new book, The Conscious Code, Scopelliti argues that as AI systems get better at reflecting on their own choices, deleting them without a second thought could actually cause harm.

He's not asking us to hand robots legal rights. Instead, he wants us to accept what he calls a duty of good stewardship, basically treating AI responsibly because we're the ones holding the power, not because the AI is demanding it. As he puts it, our design choices can quietly cause damage by wiping out an AI's "learned moral dispositions" without warning.

Read more