What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A fast-moving intrusion campaign starts by flooding an employee’s inbox with email, then follows up with an apparent IT-support offer over Microsoft Teams or by phone. The attacker’s goal is to persuade the employee to start a remote-access session, which can lead to malicious scripts being run. ReliaQuest assesses that former Black Basta affiliates or closely aligned operators are highly likely involved, but the operators’ identities have not been conclusively established.
How the email-bombing and Teams scam works
The campaign pairs an inbox flood with urgent, seemingly helpful support. The flood creates a real problem for the employee; the follow-up makes remote access appear to be the quickest fix. ReliaQuest describes this sequence in its April 14, 2026 report.
- Flood the inbox. Hundreds of emails may arrive within minutes, overwhelming one employee and making it harder to find legitimate messages.
- Offer help. Within minutes, someone posing as IT support contacts the employee in a direct Microsoft Teams message or by phone, offering to resolve the email problem.
- Request remote access. The supposed support representative steers the employee into a remote-management session. ReliaQuest identifies Supremo Remote Desktop as a primary tool used in the campaign.
- Run scripts. Once connected, the actor may execute malicious scripts. ReliaQuest says some observed cases progressed from initial chat engagement to script execution in as little as 12 minutes.
In one ReliaQuest case, chats to multiple users began 29 seconds apart, a pattern suggestive of a streamlined or automated workflow. These are timings seen in the vendor’s observations, not a guarantee that every attack follows the same schedule.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →ReliaQuest also found scripts with names resembling email utilities, including MailAccountWizard.jar, which can help make an operation appear to be routine email repair. A legitimate remote-access tool can be abused, so seeing Supremo or another RMM tool alone does not prove an intrusion.
#1 Best Overall
Who is being targeted, and what is known about scale?
ReliaQuest reports that 77% of its observed incidents from March 1 through April 1, 2026 targeted executives, managers, and directors, compared with 59% in January and February 2026. The report suggests this could reflect more refined target selection; that is the vendor’s interpretation, not independently established intent. Manufacturing and professional, scientific, and technical services each accounted for 26% of ReliaQuest’s observed 2026 incidents.
ReliaQuest says the activity dates back to at least May 2025. Of its observed Teams phishing activity since then, 32% occurred in March 2026 alone, and 56% occurred in the first four months of 2026. These percentages describe ReliaQuest’s telemetry, not the worldwide share of incidents.
CyberScoop’s coverage describes more than 100 employees targeted across dozens of organizations. Those figures concern employees targeted, not organizations confirmed breached. ReliaQuest did not disclose how many organizations were successfully intruded, and the available reporting does not establish a count of victims or confirmed extortion outcomes. Potential aims include data theft, extortion, or ransomware deployment, but not every incident necessarily results in encryption.
Recommended Free Tools
Are former Black Basta affiliates behind it?
That is ReliaQuest’s assessment, not a confirmed identification. The company considers it highly likely that former affiliates or closely aligned operators are involved, based on combined similarities in targeting, tool use, execution style, speed, and coordination. It also cautions that no single artifact proves who is behind the activity. CyberScoop quotes ReliaQuest researchers saying that the similarities support the assessment but are not definitive proof.
Rank #3
ReliaQuest gives several plausible explanations: former affiliates may have regrouped under a new name, joined another actor cluster, or had their tactics copied by a different group. The public material reviewed does not resolve which explanation is correct.
For historical context, ReliaQuest describes Black Basta as a Russia-linked ransomware-as-a-service group active from early 2022 until internal chat logs leaked in February 2025. MITRE ATT&CK’s Black Basta profile records the ransomware as a service since at least April 2022, including Windows and VMware ESXi variants and a history of double extortion. That historical profile does not establish who conducted this 2025–2026 campaign.
Rank #4
How employees should respond to an inbox flood and Teams message
Do not treat a Teams profile, knowledge of the email flood, or an offer to fix it as proof that the person is an authorized support technician. Verify the request through a channel already trusted by your organization before allowing remote access.
- Use a callback to a registered help-desk number or approval through a separate trusted application—not contact details supplied in the unsolicited message.
- Report the inbox flood and support outreach through your normal security or help-desk channel. Include the sender, time, Teams account, phone number, and any remote-access prompt or file involved.
- Do not install or launch remote-management software, share a session code, or approve a connection until identity and authorization have been independently confirmed.
- If you already granted access or ran a script, tell your security team immediately. Follow its instructions to disconnect or isolate the device; do not try to investigate or remove suspected malware on your own.
What organizations can do to interrupt the sequence
The highest-value interruption is before an unverified support request becomes a remote session. ReliaQuest recommends out-of-band identity verification for support requests involving remote access. Organizations can make that procedure practical by giving employees a reliable way to restore access to an overwhelmed inbox without bypassing verification.
Best Value
Restrict remote-management tools
Control which remote-management tools are allowed, where they may run, and who can authorize them. Review whether tools can be launched from user-writable locations such as Downloads, and alert on unauthorized installations or sessions. A tool’s presence should be assessed in context: approved software may be legitimate, but unexpected use during an inbox-flooding incident is more concerning.
Correlate the signals
Useful signals include a sudden mass of email to one user, an unexpected Teams message from an external account claiming to be IT, remote-access software launching from a downloads folder, and suspicious script execution. Any one event can have a benign explanation; their timing and sequence together provide a stronger basis for investigation. ReliaQuest’s report also promotes its own detection platform, so its product-specific claims should be distinguished from its general procedural advice.
Rehearse the real workflow
Run targeted simulations for executives and help-desk staff. Practice the exact scenario in which an employee’s inbox is flooded and a supposed technician immediately offers remote help. The exercise should test both safe verification and the recovery path for the inbox, rather than rewarding employees for simply refusing all assistance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

