<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Microsoft Shuts Down Ransomware Gang Using Fake Teams Apps

Microsoft halts a major ransomware threat by revoking 200+ certificates used by cybercriminals to disguise malware as legitimate software.
Content Team

Microsoft disrupted a major ransomware operation by revoking over 200 digital certificates that cybercriminals were using to make malware look legitimate. The Vanilla Tempest group, also known as Vice Society, created fake Microsoft Teams installers that appeared authentic thanks to stolen certificates from Microsoft's own Azure service and other providers like DigiCert and GlobalSign.

The scammers hosted these fake installers on domains like teams-download[.]buzz and used search engine tricks to lure victims. When users downloaded what they thought was Teams, they actually got the "Oyster" backdoor, which later delivered Rhysida ransomware. Vanilla Tempest has previously targeted schools and hospitals, though their latest victims remain unclear.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo