Teams Scammers Deploy Reverse Shells Through Fake IT Support Requests
Threat actors are using fake IT support requests on Microsoft Teams to trick employees into granting remote access through Quick Assist. Once granted, the attacker has hands-on control of the device and can deploy a multi-stage reverse shell.
The attackers pose as IT technicians and contact targets through external Microsoft Teams chats, convincing them that a technical problem requires remote support. The victim is then instructed to open the legitimate Quick Assist application, which allows the attacker to download a malicious MSI installer from an Amazon S3 bucket.
Instead of relying on a clearly malicious executable, the MSI package drops a legitimate signed application alongside a malicious DLL. This method makes the activity appear more trustworthy to users and some security controls.