Hackers Abuse Teams for Malware and Network Compromise
Palo Alto Networks researchers have discovered that hackers are using Microsoft Teams as an entry point to target employees. The attackers pose as IT support, creating external accounts with display names such as 'help desk' or 'IT assistance'. They use these accounts to initiate one-to-one chats on Microsoft Teams and then call the employees, sometimes leaving voicemails if they don't answer.
The campaign, tracked as Spring Ring, ran from January through April 2023 and targeted at least 150 employees across 10 organizations. The hackers did not exploit a flaw in Teams but instead abused external communication features, taking advantage of the trust users place in workplace collaboration tools.
Palo Alto Networks' Unit 42 analysts detected suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities. These attackers used external accounts that resembled internal IT support to gain access to employees' systems and networks.