Teams Phishing Scam Tricks Victims into Granting Remote Access
Microsoft has issued a warning about an ongoing hacking campaign that uses Microsoft Teams to impersonate IT staff and trick victims into granting remote access. The attackers then use this access to install malware, conduct lateral movement, and eventually deploy ransomware.
The attackers typically reach out to their targets via Teams chat, coercing them into granting access through screen sharing or remote monitoring and management tools. Once inside, the attackers map out the victim's system, enumerate domain accounts and servers, and move laterally before extracting valuable data and deploying ransomware.
Microsoft advises enterprises to harden Microsoft Teams and email against social engineering by verifying unsolicited support contacts and training employees to recognize external-tenant indicators. The company also recommends using Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) to neutralize malicious messages and URLs.