Jessica Entwistle
September 3 2026
Microsoft Threat Intelligence reports that it has observed a human-operated intrusion campaign in which attackers abuse Microsoft Teams external collaboration features to impersonate IT support staff, gain remote access to user devices, and deploy a Node.js-based implant. The attackers use social engineering to convince users to grant remote access through legitimate tools such as remote desktop software or screen sharing applications. Once access is established, the attackers move laterally within the network, escalate privileges and deploy persistent backdoors. The campaign demonstrates how collaboration tools designed to enable external communication can be exploited when users are not trained to recognise impersonation attempts or when external access controls are not properly configured. Microsoft has published detection guidance and indicators of compromise to help organisations identify and respond to this activity.
Microsoft Teams and similar collaboration platforms are now deeply embedded in how organisations communicate, both internally and with external partners, suppliers and customers. The operational risk is that users may trust messages appearing within these platforms more readily than they would trust unsolicited emails or phone calls, especially if the attacker has researched the organisation and crafted a plausible pretext. The attack also highlights the challenge of securing external collaboration features, which are often enabled by default to support business flexibility but can create pathways for social engineering if not properly governed. Once an attacker gains remote access to a single user device, they can often move laterally to other systems, access shared drives, harvest credentials and establish persistence across the environment. The challenge for organisations is that legitimate IT support often does use remote access tools and collaboration platforms to assist users, making it difficult for users to distinguish between genuine support requests and impersonation attempts without clear verification processes.
Review how external collaboration is configured in Microsoft Teams and similar platforms. Consider whether external access is restricted to known domains, whether there are controls to prevent external users from initiating contact with internal users, and whether users are trained to verify the identity of anyone requesting remote access or credentials. Organisations should review whether IT support processes are clearly documented and communicated so that users know how legitimate support requests are initiated and can recognise deviations from that process. Consider whether remote access tools are monitored and logged, whether there are alerts for unusual remote access activity, and whether there is a process for users to report suspicious contact attempts. Organisations should also assess whether security awareness training covers collaboration tool risks, impersonation techniques and verification procedures, and whether there are technical controls such as conditional access policies, multi-factor authentication and endpoint detection to limit the impact of successful social engineering. Where possible, consider implementing verification steps such as requiring users to contact IT support through a known channel before granting remote access, or using out-of-band verification for sensitive requests.
Source: Microsoft Security Blog