Impact: High
TLP Rating: Clear
CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.
On June 06th, 2023, CERT Vanuatu discovered on a number of reputable sources of a tool called “TeamsPhisher” which was developed by Security experts at the US Navy has recently discovered a flaw in Microsoft Teams.
What is it?
The “TeamPhishing” tool exploits Microsoft Teams and allow attackers to easily go around Microsoft Teams’ file-sending restraints to deliver malware from an external account.
Further Technical Details of the Exploit and Impact
(This is how the attackers use the tools to their advantage).
“TeamPhisher” first confirms the targeted user’s existence and ability to receive external messages before creating a new thread with the target and sending a SharePoint attachment link. It has a huge potential reach that could be leveraged by threat actors to bypass many traditional payload delivery security controls.
The exploit even works against accounts protected by Multi-Factor Authentication (MFA).
Mitigation Process / What should I do to Stay Safe?
The vulnerabilities utilized by “TeamsPhisher” are known and acknowledged by Microsoft, but there are currently no plans for them to be addressed.
CERTVU recommends that organizations and institutions using Microsoft Teams avoid clicking links that could be suspicious and double-verify before opening legitimate messages with a link.
We recommend Users to apply practice habits, including exercising caution when accepting file transfers, opening unknown files, and clicking on links to web pages.
References
- https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/new-tool-exploits-microsoft-teams-bug-to-send-malware-to-users/amp/?fbclid=IwAR0opJGRwWJtR58_no_V2DsCCXFN7eH_0BBm8QfiXnI8_UwoCWbQfTrXKfE
- https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/
- Download advisory (English): Microsoft Teams Exploitable by New Phishing Tool
- Download advisory (French): Microsoft Teams exploité par un nouvel outil d’hameçonnage baptisé TeamsPhisher
- Download advisory (Bislama): Wan Niu Fising (Phishing) Tul blong eksploitem Microsoft Teams