Hackers Exploit Microsoft Teams and Quick Assist to Deploy Stealthy A0Backdoor Malware
Cybersecurity researchers have uncovered a sophisticated attack campaign where hackers exploit Microsoft Teams and Windows Quick Assist to gain remote access and deploy a stealthy malware known as A0Backdoor.

Cybercriminals exploiting Microsoft Teams and Windows Quick Assist to deploy stealthy A0Backdoor malware in enterprise networks.
Cybersecurity researchers have uncovered a sophisticated attack campaign exploiting trusted enterprise tools to infiltrate corporate networks.
According to analysts at BlueVoyant, attackers are abusing collaboration platforms such as Microsoft Teams and the built-in remote support tool Windows Quick Assist to trick employees into granting system access.
Once access is obtained, threat actors deploy a newly identified malware strain known as A0Backdoor, enabling long-term stealth access to compromised systems.
Social Engineering Used to Gain Access
The attack begins with a large wave of spam emails sent to targeted employees within an organisation. The goal is to overwhelm users and create confusion around a perceived technical issue.
Shortly afterward, attackers contact the victim through Microsoft Teams while impersonating internal IT support staff.
By pretending to assist with the email issue, the attackers convince victims to launch Windows Quick Assist, a legitimate Windows feature used for remote troubleshooting.
Once the victim grants remote access, the attackers effectively bypass traditional security barriers and gain direct control of the system.
Malware Deployment Through Trusted Channels
After securing access, attackers deploy malware using digitally signed installation packages that appear legitimate.
Researchers observed that these files are often hosted on personal Microsoft cloud storage service, making them appear trustworthy to users and security systems.
The malicious installers are delivered through temporary download links, which makes retrospective analysis difficult once the links expire.
DLL Sideloading Enables Stealth Execution
Following execution, the attackers use a technique known as DLL sideloading to load malicious code while disguising it as legitimate system files.
Malicious files are placed inside hidden application directories, masquerading as components associated with:
Some files are signed with deceptive digital certificates, helping the malware bypass certain security checks and appear legitimate to system processes.
A0Backdoor Enables Covert System Access
Once activated, the loader decrypts and launches A0Backdoor, a stealthy malware designed to operate primarily in system memory.
The backdoor immediately begins collecting system information, including the device name and configuration details, allowing attackers to uniquely identify compromised machines.
To evade antivirus detection, the malware copies itself to new memory locations and avoids leaving obvious traces on the system.
DNS Tunneling Used for Hidden Communication
Instead of communicating directly with attacker-controlled servers, the malware relies on DNS tunneling to maintain covert communications.
This method allows the attackers to send commands and receive data while blending malicious traffic into normal internet activity.
Researchers also observed that attackers frequently reuse expired domain names rather than newly registered ones, helping them bypass security systems designed to block suspicious domains.
Links to Known Cybercrime Group
The campaign shares tactics with the cyber threat group Blitz Brigantine, which is widely associated with attacks involving the Black Basta ransomware operation.
This financially motivated group has previously targeted organisations in sectors such as finance and healthcare, making enterprise networks particularly vulnerable to similar social engineering campaigns.
Growing Threat to Enterprise Security
Security experts warn that the campaign demonstrates how attackers increasingly exploit trusted collaboration tools and built-in operating system utilities to bypass traditional cybersecurity controls.
The combination of social engineering, legitimate remote-access tools, memory-based malware execution, and covert communication channels represents a significant evolution in enterprise cyberattack tactics.
Organisations are being urged to strengthen employee cybersecurity awareness, implement stricter remote-access policies, and closely monitor collaboration platforms for suspicious activity.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.