Security

Cross-Tenant Teams Impersonation Attack Playbook

3 min read

Summary

Microsoft has detailed a human-operated intrusion chain where attackers use cross-tenant Microsoft Teams chats to impersonate helpdesk staff and trick users into granting remote access through tools like Quick Assist. The campaign matters because it blends legitimate collaboration, remote support, and admin tools to enable lateral movement, persistence, and data exfiltration while appearing like normal IT activity.

Need help with Security?Talk to an Expert

Introduction

Microsoft has published new threat research describing how attackers are abusing external Microsoft Teams chats to impersonate IT or helpdesk staff. For IT and security teams, this is an important reminder that modern phishing and social engineering no longer start only with email—they can begin inside trusted collaboration tools and quickly escalate into enterprise-wide compromise.

What’s new

Microsoft’s report outlines a full human-operated intrusion playbook that starts with cross-tenant Teams messages and ends with data exfiltration.

Attack chain highlighted by Microsoft

  • Initial contact via Teams: Attackers pose as support personnel using external Teams communication.
  • Remote assistance foothold: Victims are convinced to launch Quick Assist or similar remote support tools and approve access.
  • Reconnaissance and validation: Attackers quickly check user privileges, system details, and access level.
  • Trusted app abuse: Vendor-signed applications are launched with attacker-supplied modules to run malicious code.
  • Command and control: Attackers establish persistent access while blending into normal admin activity.
  • Lateral movement: Native tools such as WinRM are used to pivot toward high-value assets, including domain controllers.
  • Follow-on tooling: Commercial remote management software like Level RMM may be deployed.
  • Data exfiltration: Utilities such as Rclone are used to stage and move sensitive data to external cloud storage.

Why this matters for administrators

This campaign is notable because it relies heavily on legitimate Microsoft and third-party tools rather than obvious malware. That makes detection harder and increases the chance that activity will look like routine IT support, remote administration, or user-approved actions.

The biggest risk is not just external Teams messaging itself, but the moment a user approves remote control. Once that happens, attackers can move quickly—often within minutes—to establish broader access, deploy tools, and target identity or domain infrastructure.

Administrators should review controls across collaboration, endpoint, and identity security:

  • Harden external Teams access and review cross-tenant communication policies.
  • Train users to treat unsolicited helpdesk or security contacts in Teams with suspicion, especially first-contact messages.
  • Restrict or monitor Quick Assist and other remote support tools where possible.
  • Watch for suspicious process chains such as QuickAssist.exe followed by cmd.exe or PowerShell.
  • Monitor lateral movement activity involving WinRM and unexpected remote management software.
  • Review data exfiltration signals tied to tools like Rclone or unusual cloud storage destinations.
  • Use Microsoft Defender XDR to correlate identity, endpoint, and Teams telemetry for earlier detection.

Bottom line

Microsoft’s research shows that collaboration platforms are now part of the active intrusion landscape. Security teams should treat Teams-based impersonation and user-approved remote assistance as high-risk pathways and update monitoring, user awareness, and response playbooks accordingly.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft TeamsQuick AssistMicrosoft Defender XDRdata exfiltrationphishing

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.