Threat reportRansomwareTL-2026-0243
A0Backdoor via Microsoft Teams Social Engineering — Storm-1811/STAC5777 DNS MX C2 Covert Channel
A0Backdoor via Microsoft Teams Social Engineering (TL-2026-0243), also tracked as A0Backdoor Campaign, is a high-severity ransomware operation, first published 2026-03-17. It is attributed to Storm-1811 (Russia) with medium confidence, affects Microsoft Microsoft Teams, maps to 28 MITRE ATT&CK techniques (T1021, T1027, T1033), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 28MITRE ATT&CK
- Actors
- 2Storm-1811
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0243
- Threat ID
- TL-2026-0243
- Also known as
- A0Backdoor Campaign, Blitz Brigantine Campaign
- Severity
- HIGH
- Status
- MONITORING
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Storm-1811, Blitz Brigantine
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- financial-services, healthcare, insurance, banking, pharmaceutical
- Target regions
- North America, Europe, Asia-Pacific, United States, United Kingdom, Germany, Canada, Australia, France, Japan, South Korea, Singapore
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in A0Backdoor via Microsoft Teams Social Engineering
Malware and tooling: A0Backdoor, Black Basta - S1070, DNS MX Record Covert Channel, Microsoft Quick Assist
How A0Backdoor via Microsoft Teams Social Engineering works
Storm-1811 (STAC5777/Blitz Brigantine) deploys A0Backdoor malware via Microsoft Teams IT support impersonation and Quick Assist abuse. The backdoor uses a novel DNS MX record covert channel for C2 communication, evading traditional network monitoring. Campaign targets financial services and healthcare organizations across 10 countries, linked to Black Basta ransomware operations. Active from August 2025 through March 2026.
Storm-1811, also tracked as STAC5777 and Blitz Brigantine, is a financially motivated threat group affiliated with Black Basta ransomware-as-a-service operations. Since August 2025, the group has deployed a newly identified backdoor dubbed A0Backdoor through an increasingly refined social engineering attack chain targeting professionals in the finance and healthcare sectors.
The attack begins with an email bombing phase that floods the victim's inbox with up to 3,000 non-malicious spam messages within an hour. The threat actors then contact the victim via Microsoft Teams, impersonating internal IT support staff using tenant names such as 'Help Desk', 'Help Desk IT', 'Help Desk Support', and 'IT Support'. Display names may use homoglyphs and Unicode character substitution to bypass keyword-based filters. The actors walk the victim through installing or launching Microsoft Quick Assist, granting the adversary remote control of the device.
Once remote access is established, the operators deploy digitally signed MSI installers (Update.msi, UpdateFX.msi, or packages masquerading as Microsoft Teams Phone Link and Cross Device Add-in) hosted on personal Microsoft OneDrive cloud storage accounts via tokenized links. These MSIs contain a legitimate Windows binary, CrossDeviceService.exe, bundled with a malicious replacement of hostfxr.dll — a normally Microsoft-signed .NET host framework resolver library. The malicious hostfxr.dll is signed with a certificate issued to MULTIMEDIOS CORDILLERANOS SRL, a non-Microsoft entity.
When CrossDeviceService.exe loads the sideloaded hostfxr.dll, the malicious DLL executes embedded shellcode. The shellcode performs anti-analysis checks including sandbox detection and timing-based evasion, and spawns excessive threads via the CreateThread API to crash debuggers. It then derives an AES decryption key using SHA-256 hashing, with part of the key derived from the ASCII string 'crossdeviceservice.exe' and a trailing non-breaking space character appended to the command line. The AES-decrypted payload is the A0Backdoor, which operates entirely in memory without writing traditional file artifacts to disk.
A0Backdoor's most notable capability is its DNS MX record covert C2 channel. Rather than using HTTP/HTTPS or raw TCP callbacks, the malware crafts DNS MX queries with high-entropy, per-request subdomains that encode beacon metadata including host identifiers and counters. These queries are sent exclusively to trusted public recursive resolvers (1.1.1.1 and 8.8.8.8), ensuring traffic blends with legitimate DNS resolution. The attacker-controlled authoritative DNS server responds with MX records where the 'exchange' hostname's leftmost label encodes command/configuration data using a domain-safe alphanumeric alphabet. DNS resolvers enforce hostname syntax but do not validate that the exchange points to a working mail server, allowing this covert channel to function transparently through enterprise DNS infrastructure.
The A0Backdoor performs system enumeration using Windows APIs including DeviceIoControl, GetUserNameExW, and GetComputerNameW to fingerprint the compromised host. Post-compromise activity consistent with Storm-1811 operations includes credential harvesting, domain enumeration, lateral movement via SMB/Windows Admin Shares and RDP, deployment of additional tools (historically Cobalt Strike, ScreenConnect, NetSupport Manager), and ultimately Black Basta ransomware deployment.
BlueVoyant researchers identified at least two confirmed victims in Canada's financial sector. The broader campaign spans 10 countries: United States, United Kingdom, Germany, Canada, Australia, France, Japan, South Korea, Singapore, and Switzerland. While the A0Backdoor and DNS MX C2 represent new capabilities, the social engineering playbook is a direct evolution of Storm-1811's documented tactics dating back to May 2024.
MITRE ATT&CK techniques used in TL-2026-0243
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
discovery
T1033 System Owner/User Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery
exfiltration
T1048 Exfiltration Over Alternative Protocol
collection
T1056 Input Capture; T1074 Data Staged
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
impact
T1486 Data Encrypted for Impact; T1667 Email Bombing
persistence
T1547 Boot or Logon Autostart Execution; T1574 Hijack Execution Flow
defense-impairment
initial-access
resource-development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
stealth
Affected products and versions in A0Backdoor via Microsoft Teams Social Engineering
Remediation for A0Backdoor via Microsoft Teams Social Engineering
Immediate actions
- Block known IOC domain fsdgh.com at DNS and perimeter firewalls
- Block IP 78.46.67.201 at network perimeter
- Audit Microsoft Teams external access policies — restrict external tenant communications
- Disable or restrict Microsoft Quick Assist via Group Policy (HKLM\SOFTWARE\Policies\Microsoft\Windows\RemoteAssistance)
- Monitor for anomalous DNS MX query volume and high-entropy subdomain patterns to public resolvers
- Hunt for CrossDeviceService.exe loading unsigned or non-Microsoft-signed hostfxr.dll instances
- Block MSI execution from user-writable directories via AppLocker or WDAC policies
Workarounds
- Disable Quick Assist enterprise-wide if not operationally required
- Restrict Teams external messaging to approved domains only
- Configure DNS firewall rules to alert on MX queries to newly registered or low-reputation domains
- Enable enhanced audit logging for remote access tool usage
Longer-term hardening
- Deploy EDR with behavioral detection for DLL sideloading and in-memory payload execution
- Implement DNS security monitoring capable of detecting DNS tunneling patterns in MX queries
- Enforce conditional access policies requiring managed devices for Microsoft Teams
- Implement application allowlisting to prevent unauthorized MSI installations
- Deploy DMARC/DKIM/SPF to reduce email bombing effectiveness
- Train employees on IT support impersonation social engineering tactics
- Segment networks to limit lateral movement from compromised endpoints
- Monitor for anomalous Quick Assist and remote access tool usage patterns
Weaknesses (CWE) in A0Backdoor via Microsoft Teams Social Engineering
Timeline of A0Backdoor via Microsoft Teams Social Engineering
- CISA, FBI, HHS, and MS-ISAC release joint advisory AA24-131A on Black Basta ransomware TTPs and IOCs
- Microsoft publishes initial report on Storm-1811 misusing Quick Assist in social engineering attacks leading to Black Basta ransomware deployment
- Sophos MDR publishes report tracking 15+ incidents of STAC5777 email bombing and Teams vishing campaigns in the preceding three months
- A0Backdoor campaign first observed targeting financial services and healthcare organizations with evolved attack chain including DNS MX C2 covert channel
- Campaign evolves with refined DLL sideloading via CrossDeviceService.exe and AES-encrypted in-memory payload delivery, expanding to 10 countries
- BlueVoyant confirms at least two victims in Canadian financial sector with full A0Backdoor compromise and DNS MX C2 activity
- Latest confirmed A0Backdoor deployment observed, campaign continues actively targeting finance and healthcare sectors globally
- Multiple independent advisories published: ThaiCERT, BleepingComputer, SC Media, HivePro, CybersecurityNews, and GBHackers all report on A0Backdoor campaign
- BlueVoyant publishes comprehensive technical analysis of A0Backdoor including DNS MX C2 mechanism, DLL sideloading chain, and anti-analysis techniques
- As of 2026-05-29, this Storm-1811/Blitz Brigantine A0Backdoor campaign remains active: BlueVoyant assessed it ongoing at March 2026 disclosure (last confirmed deployment Feb 28), no CVE to patch, no infrastructure takedown, and Teams/Quick Assist vishing keeps thriving. No fresh public A0Backdoor-specific victims surfaced in Apr-May 2026, so it is downgraded to MONITORING rather than peak ACTIVE.
Sources cited for A0Backdoor via Microsoft Teams Social Engineering
- BlueVoyant — New A0Backdoor Linked to Teams Impersonation and Quick Assist Social Engineering
- BleepingComputer — Microsoft Teams Phishing Targets Employees with A0Backdoor Malware
- ThaiCERT Advisory — A0Backdoor and DNS MX C2
- SC Media — Storm-1811 Black Basta Link
- HivePro Threat Advisory — Microsoft Teams Social Engineering Delivers A0Backdoor Malware
- CybersecurityNews — Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor
- Black Hat Ethical Hacking — Attackers Impersonate IT Support on Microsoft Teams to Deploy A0Backdoor
- MITRE ATT&CK — Storm-1811 Group G1046
- SecQube — How A0Backdoor Malware Evades Detection in Microsoft Teams Environments
- Microsoft Security Blog — Threat Actors Misusing Quick Assist in Social Engineering Attacks
- Sophos MDR — Two Ransomware Campaigns Using Email Bombing and Teams Vishing
- CISA — StopRansomware: Black Basta Advisory AA24-131A
- Red Canary — Storm-1811 Exploits RMM Tools to Drop Black Basta Ransomware
- OffSeq Threat Radar — A0Backdoor Live Threat Intelligence
Detection coverage for TL-2026-0243
As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0243 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.