Cookie Consent by Free Privacy Policy Generator

Attackers impersonate IT support via Microsoft Teams

Microsoft Threat Intelligence has published research detailing a human-operated intrusion campaign that abuses Microsoft Teams external collaboration features to impersonate IT support staff. The Microsoft Security Blog reports that attackers use social engineering to convince targets to accept external Teams calls, then persuade them to grant remote access using legitimate tools such as Quick Assist or third-party remote desktop software. Once access is established, attackers deploy a Node.js-based implant and move laterally across the network using legitimate administrative tools. The campaign exploits the trust users place in internal IT support and the default external collaboration settings in Microsoft Teams, which allow external users to initiate contact with internal users.

Why this matters for UK organisations

For UK organisations using Microsoft Teams, this attack technique is particularly concerning because it leverages the collaboration tools that employees use daily and exploits the reasonable expectation that IT support may contact them. The attackers are not exploiting a technical vulnerability; they are exploiting the operational reality that users are accustomed to receiving help from IT teams and may not question an unexpected support call, especially if it appears to come through a trusted platform like Teams. The use of legitimate remote access tools also makes detection harder, as these tools are often present in enterprise environments for legitimate purposes, and their use may not trigger immediate alerts. Once an attacker has remote access to a user's device, they can harvest credentials, access internal systems, deploy malware, and move laterally across the network. The human element of this attack makes it difficult to defend against using technical controls alone; it requires a combination of configuration changes, user awareness, and monitoring.

What to review

UK businesses should review their Microsoft Teams external collaboration settings to understand who can initiate contact with internal users and whether those settings align with your risk appetite. Consider whether external access should be restricted to specific domains or disabled entirely if it is not required for business operations. Ensure users understand how your IT team actually makes contact, and establish clear verification procedures for remote access requests, such as requiring users to call a known IT support number to confirm the legitimacy of any unexpected support contact. Consider whether your security awareness training covers impersonation via collaboration platforms, and whether your monitoring can detect unusual remote access tool usage, particularly following external Teams interactions. Review whether your endpoint detection and response (EDR) tools can identify suspicious lateral movement patterns or the deployment of unusual scripts or implants. This is also a useful moment to assess whether your IT support processes are clearly documented and communicated, so that users have a reference point for what legitimate support contact looks like.

Source: Microsoft Security Blog

News and blog posts
Today's brief highlights the operational reality that security incidents often...
The Register reports that Cisco has released security updates addressing...
Krebs on Security reports that a new identity theft service launched on the...
Microsoft Threat Intelligence has published research detailing a human-operated...