Warning: This fake Microsoft Teams app is actually dangerous malware, here’s how to stay protected


  • Attackers use compromised GMX Mail accounts to send fake Microsoft Teams invitations with OAuth traps
  • Victims who authorize malicious Azure web application grant access to emails, files, and persistent account control
  • Abnormal AI calls for vigilance: check senders, inspect links, and be wary of urgent meeting requests

Scammers are sending their victims fake Microsoft Teams meeting invitations in an attempt to steal login credentials and gain persistent access to the entire Microsoft 365 ecosystem, experts have warned.

Cybersecurity experts at Abnormal AI said they recently observed the campaign in the wild. It starts with a compromised GMX Mail account. It is a free consumer email service from Germany that allows users to create up to ten sender addresses from a single account.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top