Hackers Exploit Microsoft Teams to Take Control of Windows PCs
Cybercriminals have been posing as IT technicians on Microsoft Teams to gain control of Windows PCs, according to recent reports from Unit 42. The attackers build trust with employees by contacting them through external Teams channels and asking them to open Windows Quick Assist.
Once the user approves the remote session, the attacker can download and launch a harmful installer that bypasses the need for exploiting software flaws or stealing passwords.
The campaign combines social engineering, remote-control abuse, and a hidden command channel. The attackers use Teams' built-in remote assistance feature to make their activity appear less suspicious than a conventional malware delivery attempt.