Post

Log inSign up

Post

user avatar
Unit 42
@Unit42_Intel
2023-02-13 (Monday) - Fake Microsoft Teams page on microsofteamsus[.]top pushing #IcedID (#Bokbot). Page established on Thursday, 2023-02-09, likely set up for the same type of #malvertising seen recently using Google Ads. IoCs available at bit.ly/3IiKHPq
Fake Microsoft Teams page, including download notification
Domain registered and server established for fake Microsoft Teams page on Thursday 2023-02-09
Downloaded zip contains inflated exe to install IcedID malware
Wireshark pcap showing fake teams page, malware download and IcedID infection traffic
7:39 PM · Feb 13, 202322.5KViews

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Relevant people

user avatar
Unit 42@Unit42_IntelFollow

Trending now

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up