Beware: A ransomware gang is tricking victims with fake Microsoft Teams ads



  • Rhysida spoofed Microsoft Teams ads on Bing to deliver malware via fake download pages
  • Victims received OysterLoader and Latrodectus, which deploy ransomware, backdoors, and information stealers.
  • The group operates with the RaaS model; Previous targets include US airports, libraries and school districts.

Security researchers have once again found poisoned ads on popular ad networks, spoofing major brands to deliver all sorts of nasty things.

Expel experts detected a new malware distribution campaign carried out by the Rhysida ransomware group that apparently began in June 2025 and is still ongoing at the time of this publication.



Leave a Comment

Your email address will not be published. Required fields are marked *