Digitaltrends
Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads for Malware Distribution
First seen 2 Dec 2025, 18:33 UTC
•



+3
•74% similarity
•27.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques, leveraging Microsoft code-signing certificates to appear legitimate, and has affected individuals, schools, and small businesses. The group has been active in similar campaigns since at least May 2024.
ThreatCluster AI