Beware – this fake Microsoft Teams app is actually dangerous malware, here’s how to stay protected


  • Attackers use compromised GMX Mail accounts to send fake Microsoft Teams invites with OAuth traps
  • Victims who authorize the malicious Azure Web App provide access to email, files, and persistent account control
  • Abnormal AI calls for vigilance: verify senders, inspect links, and watch out for urgent meeting requests

Scammers are sending fake Microsoft Teams meeting invitations to victims in an attempt to steal login credentials and gain persistent access across the Microsoft 365 ecosystem, experts have warned.

Cybersecurity experts from Abnormal AI said they recently observed the campaign in the wild. It starts with a compromised GMX Mail account. This is a free consumer email service from Germany that allows users to create up to ten sender addresses from a single account.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top