Microsoft Teams Call Weaponized to Deploy and Execute Matanbuchus Ransomware

A sophisticated cyberattack campaign has emerged in July 2025, weaponizing Microsoft Teams calls to deploy the latest iteration of Matanbuchus ransomware. The attack begins with adversaries impersonating IT helpdesk personnel through external Teams calls, leveragingsocial engineeringtactics to convince employees to execute malicious scripts. During thesefraudulentsupport sessions, attackers activate Quick Assist and instruct victims to run PowerShell commands that ultimately deploy the Matanbuch...

Save to Folder

Choose a folder to save this article: