Wednesday, August 12, 2026 Digital Forensics & Evidence Sign in
Lars Daniel

Digital forensics expert & expert witness · The Forbes digital forensics columnist

Digital Life & Security

Hackers Exploit Microsoft Teams In New Ransomware Scam

The Black Basta ransomware group is exploiting internal platforms like Microsoft Teams to scam employees into helping them deploy ransomware.

Virus, Malware, Cyber attack, and Internet cyber security Concept.
Black Basta ransomware group is using the internal platform of companies to social engineer ... [+] employees. · getty

The Black Basta ransomware group has begun targeting internal platforms like Microsoft Teams to exploit employees’ trust in their own organization’s communication channels.

By impersonating IT support on these trusted platforms, Black Basta is bypassing traditional external security measures and leveraging employee trust to gain access to networks.

As reported on BleepingComputer, Black Basta’s approach marks an evolving new challenge in cyber threats, highlighting that attacks can come from within as much as from outside the organization.

Why Targeting Internal Platforms is So Effective

For years, corporate security efforts have focused on blocking threats from outside the network. Email phishing filters, web monitoring, and firewalls are all designed to prevent attacks from external sources.

However, Black Basta’s approach of posing as IT support within Microsoft Teams reveals the limitations of this model. By operating within an organization’s internal communication platform, attackers can exploit employees’ inherent trust, sidestepping external security protocols entirely.

The use of Microsoft Teams means employees are more likely to trust and follow instructions received through this platform, mistakenly assuming internal messages are safe.

How Black Basta Executes the Attack

Trump Vs. Harris 2024 Polls: Harris Leads By 2 Points In New Survey—As Polls Tighten Before Election

Harris And Trump’s Biggest Celebrity Endorsements—Brett Favre Stumping For Trump In Wisconsin

Samsung’s Impossible Deadline—You Have 24 Hours To Update Your Phone

The attack typically begins when Black Basta attackers impersonate IT support on Teams, using account names like “supportadministrator” to build credibility. They often flood inboxes with junk mail or set up fake notifications to create a sense of urgency.

Once the employee engages, attackers guide them through installing remote-access tools like AnyDesk or Microsoft’s Quick Assist, which allows them to take control of the user’s device. This access is then leveraged to deploy ransomware, locking down files and demanding ransom payments. Once inside, Black Basta often employs Qakbot and Cobalt Strike to expand their reach within the network:

What is Qakbot?

Qakbot is a malware initially designed to steal banking credentials, but it has evolved into a tool for harvesting login credentials and spreading across networks. It can capture keystrokes, log passwords, and even compromise multiple devices across an organization, creating openings for other malware. Once Qakbot is installed, attackers use it to deploy additional tools like Cobalt Strike.

What is Cobalt Strike?

Cobalt Strike is a penetration testing tool designed for cybersecurity teams to simulate attacks. In the wrong hands, it becomes a powerful weapon for attackers. Cobalt Strike allows attackers to set up a “beacon,” or a secure link between themselves and the infected network, giving them control over devices and allowing them to move throughout the network. It is highly effective for lateral movement—allowing attackers to escalate privileges and deploy further malware.

Why Internal Platforms Are High-Impact Targets

High Trust Environment

Employees view platforms like Teams as part of the organization’s secure internal ecosystem. This trust is key to productivity, as it encourages open communication. However, attackers exploit this trust, knowing employees are more likely to follow instructions from an internal “IT” account without verifying its authenticity. The internal angle bypasses typical “red flags” employees might associate with phishing emails, such as unfamiliar domains or grammatical errors.

Limited Monitoring and Security Focus

Most cybersecurity measures are designed to detect threats coming from outside the network. Firewalls, email security protocols, and web filters focus on identifying and blocking threats that enter from external sources. Internal communication tools, however, are typically less scrutinized, leaving a gap in security that attackers can exploit.

Moreover, these platforms rarely have the same layers of authentication and monitoring as systems that handle sensitive data. This creates an opportunity for attackers who gain access to move laterally within the network, leveraging the openness of internal systems to access sensitive data and escalate privileges.

Ease of Social Engineering

Platforms like Microsoft Teams allow attackers to interact directly with employees, which is more effective for social engineering than traditional email-based phishing. Attackers posing as IT support can guide employees through complex steps, gaining access to high-privilege systems in real-time. This real-time interaction allows attackers to adjust their tactics based on employee responses, significantly increasing the chances of success compared to one-off phishing emails.

Growing Attack Surface with Remote Work

Remote work has increased the reliance on internal platforms for all communication, often integrating these tools directly into daily workflows. This increased use means attackers have more chances to engage with employees on these platforms. Furthermore, employees working remotely may lack quick access to in-person verification from IT teams, increasing the likelihood that they will fall for an impersonation attack.

Use of Legitimate Tools in Attacks

Many internal platforms have built-in remote-access or assistance features, like Microsoft’s Quick Assist, which attackers can exploit. Legitimate tools make the attack seem routine, avoiding detection by typical security monitoring. Attackers may ask employees to install or activate these tools, creating an appearance of legitimate IT support. Since Quick Assist and similar tools are trusted, attackers can gain remote access without raising suspicion or triggering alarms.

Protecting Internal Platforms

The Black Basta attack highlights the need to secure internal platforms. As remote and hybrid work continues, collaboration tools like Microsoft Teams will only grow in importance, and so will the associated risks.

This attack serves as a reminder that modern cybersecurity efforts must adapt to include trusted internal channels. Protecting employees from impersonation and social engineering within the organization will be as needed as safeguarding them from external threats.


This column originally appeared in Forbes.

The newsletter

Digital forensics, explained before you need it

AI evidence, deepfakes and cell phone forensics from an expert witness who works these cases. No hype, no fear-mongering. Free.

Check your inbox to confirm your subscription.