Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT

In April 2026, threat actors deployed Nimbus RAT against a legal industry target using Microsoft Teams voice phishing. The attack began with email bombing (282 emails in 90 minutes), followed by a fake IT helpdesk contact via Teams who convinced the victim to grant Quick Assist remote access. Within 20 minutes, a Java-based RAT was deployed that uses Google Drive and Google Sheets for command-and-control, making network traffic appear benign. Analysis of 1,540 suspicious Teams messages across 172 customer environments over 12 months revealed 65% originated from throwaway onmicrosoft.com tenants with IT-themed names. The malware bundles its own Java runtime, implements two credential theft mechanisms, and allows in-memory second-stage code execution. Post-compromise targeting included Signal Desktop attachments and Outlook mailboxes.

Pulse ID: 6a1ac91f182b86c3c2bcfc15
Pulse Link: https://otx.alienvault.com/pulse/6a1ac91f182b86c3c2bcfc15
Pulse Author: AlienVault
Created: 2026-05-30 11:25:19

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Email #Google #InfoSec #Java #Malware #Microsoft #MicrosoftTeams #Nim #OTX #OpenThreatExchange #Outlook #Phishing #RAT #SMS #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

What's New in Office 365, Tuesday, June 02, 2026
14 new posts across 7 Microsoft websites since Friday, May 29, 2026

#Microsoft365 #Office365 #MicrosoftTeams #Microsoft365Copilot #MicrosoftAzure

• Azure AI Foundry Blog (7)
• Microsoft Azure Blog (1)
• Microsoft Security Blog (2)

..and more: https://o365.cannell.org/2026/06/02/whats-new-in-O365.html

What’s New in Office 365 - Tuesday, June 02, 2026

14 new posts across 7 Microsoft websites since Friday, May 29, 2026<ul><li>Copilot for Microsoft 365 (1)</li><li>Microsoft Copilot Studio Blog (1)</li><li>Microsoft Azure Blog (1)</li><li>Microsoft Security Blog (2)</li><li>Education Blog (1)</li><li>Skype for Business Blog (1)</li><li>Azure AI Foundry Blog (7)</li></ul>

What’s New in Office 365

Helpdesk Shenanigans Surface as "Fake IT Support" Scams Escalate

Cybercriminals impersonate IT helpdesks on Teams, while a Canadian IT team faces claims of faking work. See how this affects employees and security.

#FakeITSupport, #CyberScams, #MicrosoftTeams, #WorkplaceIssues, #CanadaNews

https://newsletter.tf/fake-it-support-scams-canada-helpdesk-teams/

New scams are using fake IT support on platforms like Teams. This is more dangerous than old email scams because it happens in real-time.

#FakeITSupport, #CyberScams, #MicrosoftTeams, #WorkplaceIssues, #CanadaNews
https://newsletter.tf/fake-it-support-scams-canada-helpdesk-teams/

Fake IT Scams Rise While Canada Helpdesk Faces Internal Issues

Cybercriminals impersonate IT helpdesks on Teams, while a Canadian IT team faces claims of faking work. See how this affects employees and security.

NewsletterTF

Who is the celebrity in Microsoft Teams Don't Miss the Goal ad?

#MicrosoftTeams #abancommercials Discover the celebrity featured in the Microsoft Teams "Don't Miss

the Goal" ad. Uncover insights and details about this exciting

collaboration today!

https://abancommercials.com/art-ad/en/16451/who-is-the-celebrity-in-microsoft-teams-don-apost-miss-the-goal-ad

Who is the celebrity in Microsoft Teams Don't Miss the Goal ad?

Discover the celebrity featured in the Microsoft Teams "Don't Miss the Goal" ad. Uncover insights and details about this exciting c

For those people like me, who uses M$ Teams at work:

How do you use Teams from a mobile browser?
Is there a trick to do it without using desktop mode?

Any fdroid app to use?
I really don't wanna install Microsoft teams on my mobile phone, but it's super handy to just message colleagues when being late and so on...

P.S.: I REALLY HATE TEAMS

#teams #Microsoft #MsTeams #microsoftTeams #fdroid #android

Microsoft Probes Office Apps, Teams File Access Outage

Microsoft is currently investigating an issue that's preventing some users from accessing files in Office for the web and Microsoft Teams, with affected users seeing an error message stating that Office Online services are temporarily unavailable. The company is working to restore services as soon as possible.

https://osintsights.com/microsoft-probes-office-apps-teams-file-access-outage?utm_source=mastodon&utm_medium=social

#Microsoft365 #OfficeApps #MicrosoftTeams #ServiceOutage #EmergingThreats

Microsoft Probes Office Apps, Teams File Access Outage

Microsoft investigates Office apps and Teams file access outage, find out what's happening and how to stay updated on the status of this ongoing incident now.

OSINTSights

c’t-Workshop: Microsoft 365 im Team produktiv nutzen

Lernen Sie, wie Sie mit klaren Strukturen und passenden Werkzeugen die Zusammenarbeit in Microsoft 365 spürbar verbessern und Dateichaos vermeiden.

https://www.heise.de/news/c-t-Workshop-Microsoft-365-im-Team-produktiv-nutzen-11307709.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#IT #Microsoft #Microsoft #MicrosoftTeams #news

c’t-Workshop: Microsoft 365 im Team produktiv nutzen

Lernen Sie, wie Sie mit klaren Strukturen und passenden Werkzeugen die Zusammenarbeit in Microsoft 365 spürbar verbessern und Dateichaos vermeiden.

heise online