# A0Backdoor via Microsoft Teams Social Engineering — Storm-1811/STAC5777 DNS MX C2 Covert Channel

> Storm-1811 (STAC5777/Blitz Brigantine) deploys A0Backdoor malware via Microsoft Teams IT support impersonation and Quick Assist abuse. The backdoor uses a novel DNS MX record covert channel for C2 communication, evading traditional network monitoring. Campaign targets financial services and healthcare organizations across 10 countries, linked to Black Basta ransomware operations. Active from August 2025 through March 2026.

- **Published:** 2026-03-17T12:00:00Z
- **Last reviewed:** 2026-03-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0243
- **ID:** TL-2026-0243
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** MONITORING
- **Actor:** Storm-1811 (Russia)
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Storm-1811, also tracked as STAC5777 and Blitz Brigantine, is a financially motivated threat group affiliated with Black Basta ransomware-as-a-service operations. Since August 2025, the group has deployed a newly identified backdoor dubbed A0Backdoor through an increasingly refined social engineering attack chain targeting professionals in the finance and healthcare sectors.

The attack begins with an email bombing phase that floods the victim's inbox with up to 3,000 non-malicious spam messages within an hour. The threat actors then contact the victim via Microsoft Teams, impersonating internal IT support staff using tenant names such as 'Help Desk', 'Help Desk IT', 'Help Desk Support', and 'IT Support'. Display names may use homoglyphs and Unicode character substitution to bypass keyword-based filters. The actors walk the victim through installing or launching Microsoft Quick Assist, granting the adversary remote control of the device.

Once remote access is established, the operators deploy digitally signed MSI installers (Update.msi, UpdateFX.msi, or packages masquerading as Microsoft Teams Phone Link and Cross Device Add-in) hosted on personal Microsoft OneDrive cloud storage accounts via tokenized links. These MSIs contain a legitimate Windows binary, CrossDeviceService.exe, bundled with a malicious replacement of hostfxr.dll — a normally Microsoft-signed .NET host framework resolver library. The malicious hostfxr.dll is signed with a certificate issued to MULTIMEDIOS CORDILLERANOS SRL, a non-Microsoft entity.

When CrossDeviceService.exe loads the sideloaded hostfxr.dll, the malicious DLL executes embedded shellcode. The shellcode performs anti-analysis checks including sandbox detection and timing-based evasion, and spawns excessive threads via the CreateThread API to crash debuggers. It then derives an AES decryption key using SHA-256 hashing, with part of the key derived from the ASCII string 'crossdeviceservice.exe' and a trailing non-breaking space character appended to the command line. The AES-decrypted payload is the A0Backdoor, which operates entirely in memory without writing traditional file artifacts to disk.

A0Backdoor's most notable capability is its DNS MX record covert C2 channel. Rather than using HTTP/HTTPS or raw TCP callbacks, the malware crafts DNS MX queries with high-entropy, per-request subdomains that encode beacon metadata including host identifiers and counters. These queries are sent exclusively to trusted public recursive resolvers (1.1.1.1 and 8.8.8.8), ensuring traffic blends with legitimate DNS resolution. The attacker-controlled authoritative DNS server responds with MX records where the 'exchange' hostname's leftmost label encodes command/configuration data using a domain-safe alphanumeric alphabet. DNS resolvers enforce hostname syntax but do not validate that the exchange points to a working mail server, allowing this covert channel to function transparently through enterprise DNS infrastructure.

The A0Backdoor performs system enumeration using Windows APIs including DeviceIoControl, GetUserNameExW, and GetComputerNameW to fingerprint the compromised host. Post-compromise activity consistent with Storm-1811 operations includes credential harvesting, domain enumeration, lateral movement via SMB/Windows Admin Shares and RDP, deployment of additional tools (historically Cobalt Strike, ScreenConnect, NetSupport Manager), and ultimately Black Basta ransomware deployment.

BlueVoyant researchers identified at least two confirmed victims in Canada's financial sector. The broader campaign spans 10 countries: United States, United Kingdom, Germany, Canada, Australia, France, Japan, South Korea, Singapore, and Switzerland. While the A0Backdoor and DNS MX C2 represent new capabilities, the social engineering playbook is a direct evolution of Storm-1811's documented tactics dating back to May 2024.

## MITRE ATT&CK

- T1667 Email Bombing
- T1684.001 Impersonation
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1622 Debugger Evasion
- T1553 Subvert Trust Controls
- T1056 Input Capture
- T1033 System Owner/User Discovery
- T1482 Domain Trust Discovery
- T1087 Account Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1074 Data Staged
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1219 Remote Access Tools
- T1048 Exfiltration Over Alternative Protocol
- T1486 Data Encrypted for Impact
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1588 Obtain Capabilities

## Sources

- [BlueVoyant — New A0Backdoor Linked to Teams Impersonation and Quick Assist Social Engineering](https://www.bluevoyant.com/blog/new-a0backdoor-linked-to-teams-impersonation-and-quick-assist-social-engineering)
- [BleepingComputer — Microsoft Teams Phishing Targets Employees with A0Backdoor Malware](https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-targets-employees-with-backdoors/)
- [ThaiCERT Advisory — A0Backdoor and DNS MX C2](https://www.thaicert.or.th/advisory/a0backdoor-storm-1811)
- [SC Media — Storm-1811 Black Basta Link](https://www.scworld.com/news/a0backdoor-storm-1811-black-basta)
- [HivePro Threat Advisory — Microsoft Teams Social Engineering Delivers A0Backdoor Malware](https://hivepro.com/threat-advisory/microsoft-teams-social-engineering-delivers-a0backdoor-malware/)
- [CybersecurityNews — Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor](https://cybersecuritynews.com/attackers-abuse-microsoft-teams-to-drop-a0backdoor/)
- [Black Hat Ethical Hacking — Attackers Impersonate IT Support on Microsoft Teams to Deploy A0Backdoor](https://www.blackhatethicalhacking.com/news/attackers-impersonate-it-support-on-microsoft-teams-to-deploy-a0backdoor-malware/)
- [MITRE ATT&CK — Storm-1811 Group G1046](https://attack.mitre.org/groups/G1046/)
- [SecQube — How A0Backdoor Malware Evades Detection in Microsoft Teams Environments](https://www.secqube.com/blog/how-a0backdoor-malware-evades-detection-in-microsoft-teams-collaboration-environments)
- [Microsoft Security Blog — Threat Actors Misusing Quick Assist in Social Engineering Attacks](https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/)
- [Sophos MDR — Two Ransomware Campaigns Using Email Bombing and Teams Vishing](https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing)
- [CISA — StopRansomware: Black Basta Advisory AA24-131A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a)
- [Red Canary — Storm-1811 Exploits RMM Tools to Drop Black Basta Ransomware](https://redcanary.com/blog/threat-intelligence/storm-1811-black-basta/)
- [OffSeq Threat Radar — A0Backdoor Live Threat Intelligence](https://radar.offseq.com/threat/new-a0backdoor-linked-to-teams-impersonation-and-q-a3cec5d5)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0243
