Microsoft Teams Hackers Pose as IT Support to Gain Enterprise Control
Hackers have been impersonating IT support on Microsoft Teams to gain control of employee PCs. This human-operated intrusion campaign uses external collaboration to pose as internal staff, convincing employees to grant remote access. The attackers then move towards critical enterprise infrastructure.
The campaign does not exploit a vulnerability in Microsoft Teams but instead exploits trust in familiar support workflows. It combines various tools and protocols, including Teams chats or calls, remote-assistance tools, PowerShell, malicious MSI installers, portable Node.js binaries, and native Windows administration protocols.
Once the attacker gains control of a PC, they can progress from a single device to domain controllers and certificate authorities. The attackers initiate contact from an external Microsoft 365 tenant while posing as IT support personnel.