Q3 2024 delivered a sobering mix of aggressive ransomware campaigns, exploitation of communication tools, and the erosion of trust in core infrastructure systems. While many security teams focused on patching high-profile CVEs, attackers shifted toward persistent access, cloud pivoting, and identity-layer abuse.
From Microsoft Teams and Telegram exploits to quiet surveillance implants in mobile apps, Q3 proved that the easiest way into your system is often the one you already trust.
Here’s what defined the quarter.
1.Black Basta ransomware campaign expands through third-party IT providers
Wave observed: July–August 2024
Black Basta, one of the most financially successful ransomware groups of 2023, launched a targeted campaign against managed service providers (MSPs) and IT support firms.
By compromising one vendor, attackers spread laterally across client environments using shared RMM tools, PowerShell scripts, and shadow admin accounts.
Victims included legal firms, architecture firms, and mid-sized manufacturers across the U.S. and DACH region.
In several cases, EDR tools were disabled using stolen MSP credentials.
2.Microsoft Teams file spoofing vulnerability leads to phishing and malware delivery
Disclosed: August 2024
A critical vulnerability allowed attackers to send files in Microsoft Teams chats using spoofed sender identities, bypassing Microsoft Defender for Office 365.
This was used to distribute loader-stage malware disguised as PDFs and meeting notes, primarily targeting HR and finance teams.
While Microsoft released a patch within two weeks, threat actors had already exploited the flaw in several high-profile BEC (business email compromise) incidents.
3.Telegram bot API leveraged for real-time credential exfiltration
Observed: July–September 2024
Multiple stealer malware families were found using Telegram bots as exfiltration channels, taking advantage of the encrypted, persistent nature of Telegram APIs.
Data stolen included browser-stored credentials, Discord tokens, VPN configurations, and wallet seed phrases.
Telegram responded by blocking several abusive bot accounts, but no structural changes were made to the API model.
4.SilentPush incident reveals weaknesses in threat intel integrations
Incident disclosed: August 2024
A misconfiguration at a popular threat intelligence platform, SilentPush, led to the unintentional exposure of internal connector tokens used by enterprises to sync feeds.
This raised concerns about the security of API-based integrations between threat intelligence sources and SIEM/SOAR platforms, especially when stored statically in cloud dashboards.
5.Android spyware “GoldenFox” hits corporate BYOD environments
Discovered: September 2024
Security researchers identified a new mobile surveillance toolkit, GoldenFox, disguised as a battery-saving app. Once installed, it silently recorded:
– Clipboard content
– Screenshots
– WhatsApp/Slack messages
– SMS-based OTPs
GoldenFox primarily targeted Android users in BYOD environments in India, Singapore, and the UAE, with infections spreading through non-Google Play marketplaces and malicious SMS links.
What stood out this quarter
- Trusted platforms are now active payload channels. Microsoft Teams and Telegram were both used to deliver malware through built-in, legitimate features.
- Threat intel tools are a risk if misconfigured. Static tokens, OAuth connectors, and poorly scoped API keys need the same scrutiny as production code.
- Identity is still the softest layer. Ransomware, phishing, and surveillance campaigns all pivoted through weak credential management and assumed trust.
Final word
Q3 2024 was a reminder that what feels secure is often just familiar.
Your MSP may be your weakest link.
Your threat intel tool may be silently exposed.
And the chat window where your team shares files may be the next backdoor.
