Warning: Ransomware gang deceives victims with fake Microsoft Teams ads


  • Rhysida spoofed Microsoft Teams ads on Bing to deliver malware via fake download pages
  • Victims received OysterLoader and Latrodectus, which deploy ransomware, backdoors and infostealers
  • The group operates on the RaaS model; Past targets include US airports, libraries and school districts

Security researchers have once again discovered poison ads on popular ad networks, spoofing big brands to deliver all sorts of nastiness.

Expel experts have spotted a new malware distribution campaign led by the Rhysida ransomware group that apparently began in June 2025 and is still ongoing at the time of publication.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top