Beware – the ransomware gang is tricking victims with fake Microsoft Teams ads


  • Rhysida spoofed Microsoft Teams ads on Bing to deliver malware via fake download pages
  • Victims received OysterLoader and Latrodectus, which deploy ransomware, backdoors, and info stealers
  • The group operates according to the RaaS model; past targets include airports, libraries and US school districts

Security researchers have once again found poisoned ads on popular ad networks that spoof big brands to deliver all sorts of nastiness.

Experts at Expel discovered a new malware distribution campaign by the Rhysida ransomware group that apparently began in June 2025 and is still ongoing at press time.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top