Affected Systems
Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider). Campaigns target CEOs, IT help desk impersonation via Teams external collaboration, and government-themed tax lures (U.A.E./India). The Gentlemen ransomware operation (Gold Sherwood) claimed 683 victims through July 2026.
Exploitation Status
Active exploitation confirmed. Multiple concurrent campaigns: Spring Ring vishing operation (Jan-Apr 2026, 150+ employees targeted), Microsoft Teams-based IT impersonation with RMM tool deployment, BlueKit PhaaS targeting financial industry CEOs, Outsider PhaaS with 700+ new phishing pages post-takedown, and The Gentlemen ransomware (169 victims in July 2026 alone). No specific CVEs; attacks leverage social engineering, legitimate tools (Teams, RMM software), DLL sideloading, and OAuth abuse.
Business Impact
High impact to identity and access management: compromised Dropbox accounts provide attackers with stored corporate data and potential pivot points. Teams-based vishing grants interactive access to internal infrastructure via RMM tools, leading to PowerShell-based implant deployment, Active Directory reconnaissance, screenshot capture, and lateral movement to domain controllers via WinRM. NTLM relay attacks targeting domain controllers observed in advanced Spring Ring variants. BlueKit browser-in-the-middle attacks enable credential and session theft from financial executives. Ransomware affiliates demonstrate repeatable playbook with EDR evasion, backup disruption, and data exfiltration. Attacks abuse trusted applications and validly signed executables, bypassing traditional security controls.
Urgency
🔴 Immediate
Recommended Actions
- Restrict Microsoft Teams external collaboration: disable or limit external access in Teams admin center, enforce domain allowlists, and monitor external chat/call attempts via Microsoft 365 Defender logs.
- Block unauthorized RMM tools: implement application control policies to prevent installation of AnyDesk, TeamViewer, and similar remote access software without IT approval; monitor for silent MSI installations via PowerShell.
- Enable phishing-resistant MFA: deploy FIDO2/WebAuthn authentication for all users, prioritizing executives and privileged accounts to mitigate OAuth traps and browser-in-the-middle attacks.
- Audit Dropbox account access: force password resets for compromised accounts, review OAuth app permissions and revoke suspicious third-party integrations, enable SSO with conditional access policies.
- Monitor for NTLM relay and lateral movement: disable NTLM where possible, enable SMB signing and LDAP channel binding on domain controllers, alert on WinRM connections from non-administrative hosts, and review PowerShell script block logging for obfuscated JavaScript or Node.js runtime staging.
