Digitaltrends
Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads for Malware Distribution
First seen 2 Dec 2025, 18:33 UTC
•



+3
•27.9
Export
Article Content
Browse articles
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques, leveraging Microsoft code-signing certificates to appear legitimate, and has affected individuals, schools, and small businesses. The group has been active in similar campaigns since at least May 2024.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Critical Vulnerabilities in ConnectWise ScreenConnect Exploited in Active Attacks
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
Revival of Black Basta Tactics: Targeting Executives with Automated Phishing
The Gentlemen Ransomware Group Exploits Fortinet Flaws and AI Tools
New Mistic Backdoor Linked to Ransomware Access Broker Activity