Bobby Trapped Phishing Attacks Hijack Microsoft Teams to Spread Malware Is Your Organization at Risk?
Cybercriminals are exploiting legitimate collaboration tools in increasingly sophisticated ways.

Attackers Use Microsoft Teams Calls to Deploy Matanbuchus Ransomware
Cybercriminals are exploiting legitimate collaboration tools in increasingly sophisticated ways. One recent tactic involves using Microsoft Teams calls as a delivery vector for Matanbuchus ransomware, marking a critical shift in how attackers infiltrate corporate networks.
Our team has mapped out this attack vector across typical enterprise infrastructure to help businesses identify weak points and proactively defend their digital environments.
Infrastructure Map: How the Attack Works
Initial Contact
Attackers initiate a Microsoft Teams call to the target under the guise of a legitimate contact. This social engineering step is crucial to gain trust.
Booby-Trapped Payload Delivery
During or after the call, the attacker sends a malicious link or file, disguised as a document or update. The payload carries a booby-trapped LNK or MSI file that bypasses basic user suspicion.
Execution & Loader Deployment
Once opened, the file executes the Matanbuchus loader, which is designed to silently download and install the ransomware or additional tools like Cobalt Strike beacons.
Lateral Movement & Data Exfiltration
After gaining a foothold, the attackers move laterally within the network, exfiltrating sensitive data and preparing systems for encryption.
Ransomware Activation
The final stage involves triggering the ransomware across critical systems, followed by a ransom demand.
Companies often underestimate internal communication tools as threat vectors. This incident reinforces the need for deep behavioral monitoring across collaboration platforms.
| IOC Type | Value |
|---|---|
| Suspicious Domain | bretux[.]com |
| Hash (SHA256) | da9585d578f367cd6cd4b0e6821e67ff02eab731ae78593ab69674f649514872 |
| Malicious C2 infrastructure | 94.159.113[.]33 – fixuplink[.]com |
| Malicious update location | notepad-plus-plu[.]org |
| Malicious C2 infrastructure | nicewk[.]com |
| Scheduled Task Name | EventLogBackupTask |
Stay Protected
Don’t wait until Teams becomes your weakest link. Let’s secure your infrastructure, end to end.



