Microsoft has issued a warning about an active scam campaign involving attackers impersonating IT helpdesk staff on Microsoft Teams. This scheme leads to unauthorized remote access, malware installation, espionage, and ultimately ransomware attacks across enterprise networks.

  • Attackers impersonate IT helpdesk via Microsoft Teams chat.
  • They gain remote access, install malware, then carry out espionage and ransomware.
  • Microsoft advises user education, authentication phrases, and enhanced email defenses.

What happened

A new hacking campaign uses Microsoft Teams as the entry point, with attackers impersonating IT support personnel. They initiate contact through Teams messages, persuading employees at various organizations to allow remote screen sharing or monitoring using legitimate management tools. This access enables them to deploy malware loaders and implants that serve as the first step of a multi-stage attack.

Once inside the system, the attackers perform host reconnaissance, identify security software and virtual environments, and periodically capture desktop screens to gather intelligence. They leverage native Windows tools and Active Directory Service Interfaces to enumerate user accounts, servers, and resources, then move laterally across the network to identify valuable data before initiating ransomware infections.

Why it matters

This campaign highlights the evolving sophistication of cybercriminals who use trusted internal communication platforms like Microsoft Teams to bypass security measures. By masquerading as legitimate IT staff, attackers exploit employee trust and weaken organizational defenses through social engineering. The combination of espionage, data theft, and ransomware poses a severe risk to enterprise operations and data privacy.

The involvement of multiple threat groups employing similar tactics, including historically notable adversaries such as Cozy Bear and FIN7, demonstrates the widespread nature of this threat. It underscores the urgency for enterprises to not only deploy technical security controls but also enhance staff awareness to identify suspicious support requests, particularly those coming from external tenants.

What to watch next

Organizations should monitor for suspicious Teams activity, especially unsolicited support requests, and implement strict verification procedures like unique helpdesk authentication phrases. Strengthening Microsoft Teams and email defenses with tools such as Microsoft Defender for Office 365, Safe Links, and Zero-hour Auto Purge will help mitigate malicious messages and URLs.

Security teams must also continue to track updates from Microsoft and cybersecurity communities for evolving attack techniques in this domain. As attackers adapt, enterprises need to bolster both technological and procedural safeguards to prevent similar impersonation schemes and limit the impact of potential breaches or ransomware incidents.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings