Microsoft Warns of Teams Phishing Scams Targeting High-Value Identity Systems
Microsoft has issued a warning about a campaign in which attackers impersonate internal IT staff on Microsoft Teams, convincing employees to grant remote access. This allows them to move towards high-value identity systems.
The attack starts with an external contact initiating a chat or call with an employee and asking them to approve a screen-share 'request control' prompt or open Quick Assist using a connection code.
Once inside the device, the attacker uses PowerShell to download and silently install a malicious Windows Installer package. This includes update-themed names such as 'devfix' and 'Hotfix.'
The attackers then map the compromised environment, taking periodic screenshots and identifying domain accounts, users, and servers using Windows tools.