Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Microsoft Teams Becomes Prime Hunting Ground As It Impersonators Turn Remote Support Into Full Network Takeover

Card image cap

Attackers keep finding new ways to slip past defenses. One method now dominates initial access attempts across enterprises. They pose as internal IT staff on Microsoft Teams, convince employees to hand over remote control of their machines, and then move quietly through the network using the very tools administrators rely on every day.

This approach isn’t new. But fresh reporting shows it has matured into a reliable playbook that bypasses traditional email filters and endpoint alerts. The latest details come from a Microsoft Security Blog post published September 2 that maps an entire human-operated intrusion chain. Attackers start with a simple Teams message or call from an external tenant. They claim to be fixing a problem. Within minutes they gain interactive access.

Once inside, the real work begins. “The campaign follows a multi-stage attack chain that progresses from social engineering through payload delivery, execution, reconnaissance, and ultimately lateral movement,” Microsoft researchers wrote. The post details how operators avoid noisy malware. They favor living-off-the-land binaries and legitimate remote management software.

Consider the opening move. An account from outside the organization appears in Teams with a display name like “IT Help Desk” or “Support Staff.” The profile uses a .onmicrosoft.com address crafted to look familiar. External tenant warnings flash. Many users ignore them. A voice call follows. The conversation sounds routine. “Your machine is showing errors. Let me walk you through a quick fix.”

Success rates climb when attackers reference real company issues. Some campaigns begin with email bombing to create panic. The fake support person then offers immediate relief. Employees open Quick Assist, read out a six-digit code, or approve a screen-sharing control request. Control switches hands. The attacker now operates the desktop as if sitting at the victim’s chair.

From there the intrusion accelerates. Microsoft observed operators launching trusted applications to run malicious code. They drop payloads into ProgramData folders and use DLL side-loading against signed executables. Names such as AcroServicesUpdater2_x64.exe appear in logs. The technique lets malicious modules execute under the cover of legitimate processes.

Reconnaissance comes next. Attackers run basic commands to map the environment. They query domain controllers. They enumerate users and groups. PowerShell scripts download additional tools. In one variant documented by Palo Alto Networks’ Unit 42, operators pushed an obfuscated remote access trojan from domains like san-sid[.]com. The CyberPress article from September 3 reports that the operation, named Spring Ring, contacted more than 150 employees at a minimum of 10 organizations between January and April 2026.

Unit 42 researchers broke the activity into two paths. One relied on remote monitoring tools for interactive access. The other escalated to NTLM relay attacks aimed at domain controllers. Calls typically lasted 10 to 15 minutes when successful. Many attempts lasted only seconds as operators moved rapidly down target lists. They created 26 distinct attacker identities with names designed to build trust. “ITProtectionDepartment” and “MandatoryNetworkMonitoring” stood out.

The blending of legitimate tools creates real detection headaches. Microsoft notes that Teams applies labels for external contacts. It shows prompts and phishing indicators. Yet the attack depends on user approval. Once granted, the session looks like normal support activity. Quick Assist and similar utilities generate expected network traffic. Administrative protocols such as WinRM appear in logs without raising alarms.

Data exfiltration follows the same pattern. Operators stage files in standard directories. They use rclone or other approved cloud sync utilities to move information to external storage. No custom exfiltration binaries. No obvious command-and-control beacons in many cases. The entire operation hides inside expected enterprise workflows.

Earlier campaigns laid the groundwork. A Register story from April 2026 described UNC6692, a group that combined email flooding with Teams helpdesk impersonation. Victims received overwhelming spam, then a helpful message offering a “patch.” The link led to an AutoHotkey script that installed a malicious browser extension called SNOWBELT.

Other reports tie the tactic to ransomware crews. Sophos tracked activity that led to Chaos ransomware deployment in under 17 hours in one case. Black Basta affiliates adopted the method early. The pattern repeats because it works. Employees trust their IT department. They want to be helpful. A polite voice on the other end of a Teams call lowers defenses faster than any email ever could.

Defenders face a difficult balance. Blocking all external Teams collaboration would break legitimate business processes. Many organizations partner with vendors who need to communicate this way. The solution lies in layered controls and user awareness. Microsoft recommends strict policies on remote assistance tools. Limit Quick Assist availability. Require out-of-band verification for any unexpected support request.

Monitoring helps too. Look for rapid sequences of Teams external chats followed by process executions. Track launches of Quick Assist, AnyDesk, or similar utilities from unusual accounts. Audit the Unified Audit Log for cross-tenant activity. Correlate with endpoint logs showing WinRM or PowerShell spawning from remote sessions.

Yet technology alone won’t stop every attempt. The human element remains central. Training must emphasize that legitimate IT staff rarely ask users to read codes over the phone or approve remote control without prior tickets. Companies should establish clear verification procedures. A quick call to the real helpdesk number can break the illusion.

The September Microsoft analysis marks the latest evolution. Attackers now chain these initial footholds into broader access. They move from one compromised workstation toward identity infrastructure. They target domain controllers. They seek administrative credentials. What starts as a single helpful conversation can end with enterprise-wide compromise.

Security teams already see the volume rising. Phishing alerts tied to collaboration tools jumped significantly in recent months. Unit 42 reported that such alerts made up 42 percent of all phishing detections in one period, up from 30 percent earlier. KnowBe4 data showed Teams-based attacks increasing 41 percent in a six-month window.

This surge reflects a broader shift. Adversaries prefer techniques that exploit trust over those that require software vulnerabilities. Patches close bugs. Training and process changes close human gaps. But changing behavior takes time. Meanwhile the attacks continue.

Organizations that treat Teams as just another chat application do so at their peril. The platform now serves as both productivity tool and primary attack surface. External access features that once seemed convenient have become gateways. Attackers don’t need to break in. Employees open the door for them.

The playbook is public. The indicators are documented. Microsoft, Unit 42, and others have shared exact account patterns, process names, and command sequences. The question is whether security operations centers can turn that knowledge into faster detection and response. Because the next call from “IT Help Desk” is likely already queued.