Alpha Cyber

Bobby Trapped Phishing Attacks Hijack Microsoft Teams to Spread Malware Is Your Organization at Risk?

Cybercriminals are exploiting legitimate collaboration tools in increasingly sophisticated ways.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Matanbuchus Ransomware

Attackers Use Microsoft Teams Calls to Deploy Matanbuchus Ransomware


Cybercriminals are exploiting legitimate collaboration tools in increasingly sophisticated ways. One recent tactic involves using Microsoft Teams calls as a delivery vector for Matanbuchus ransomware, marking a critical shift in how attackers infiltrate corporate networks.

Our team has mapped out this attack vector across typical enterprise infrastructure to help businesses identify weak points and proactively defend their digital environments.

Infrastructure Map: How the Attack Works


Initial Contact
Attackers initiate a Microsoft Teams call to the target under the guise of a legitimate contact. This social engineering step is crucial to gain trust.

Booby-Trapped Payload Delivery
During or after the call, the attacker sends a malicious link or file, disguised as a document or update. The payload carries a booby-trapped LNK or MSI file that bypasses basic user suspicion.

Execution & Loader Deployment
Once opened, the file executes the Matanbuchus loader, which is designed to silently download and install the ransomware or additional tools like Cobalt Strike beacons.

Lateral Movement & Data Exfiltration
After gaining a foothold, the attackers move laterally within the network, exfiltrating sensitive data and preparing systems for encryption.

Ransomware Activation
The final stage involves triggering the ransomware across critical systems, followed by a ransom demand.

Companies often underestimate internal communication tools as threat vectors. This incident reinforces the need for deep behavioral monitoring across collaboration platforms.

IOC TypeValue
Suspicious Domainbretux[.]com
Hash (SHA256)da9585d578f367cd6cd4b0e6821e67ff02eab731ae78593ab69674f649514872
Malicious C2 infrastructure94.159.113[.]33fixuplink[.]com
Malicious update locationnotepad-plus-plu[.]org
Malicious C2 infrastructurenicewk[.]com
Scheduled Task NameEventLogBackupTask

Stay Protected

Don’t wait until Teams becomes your weakest link. Let’s secure your infrastructure, end to end.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]