Microsoft Teams IT Support Scam Enables Enterprise Access
Summary
Microsoft Threat Intelligence detailed a human-operated attack that abuses Microsoft Teams external collaboration to impersonate IT support and trick users into granting remote access. Once inside, attackers use legitimate tools like PowerShell, MSI installers, Node.js, and WinRM to establish persistence, conduct reconnaissance, and move laterally toward high-value systems such as domain controllers.
Microsoft Teams IT Support Scam Enables Enterprise Access
Introduction
Microsoft has published new threat intelligence on a high-impact social engineering campaign that starts in Microsoft Teams and can end with enterprise-wide compromise. For IT and security teams, this matters because the attack relies on legitimate collaboration and admin tools, making it harder to distinguish from normal support activity.
What’s happening
Attackers are impersonating IT or helpdesk staff through Microsoft Teams external chats or calls. The goal is to persuade a user to approve a remote support session, such as a Teams screen-share control request or a Quick Assist connection.
Once access is granted, the campaign quickly escalates:
- PowerShell downloads a malicious MSI from cloud storage
- The MSI silently installs a loader and encrypted JavaScript implant
- If needed, the attacker fetches a portable Node.js runtime to execute the implant
- The malware uses HTTPS polling for command-and-control
- Operators perform host, security product, and Active Directory reconnaissance
- Additional payloads may run through trusted binaries like rundll32
- Lateral movement occurs over WinRM (TCP 5985) toward systems like domain controllers and certificate authorities
Why this is significant
This is not a typical phishing attack that stops at credential theft. Microsoft describes it as a hands-on-keyboard intrusion that gives an external operator interactive, credential-backed access inside the environment.
Because the activity uses trusted tools—Teams, remote support software, Windows Installer, PowerShell, Node.js, and native Windows admin protocols—it can blend into expected enterprise operations. That raises the risk of:
- Privilege escalation
- Data theft
- Security control tampering
- Ransomware deployment
- Broader domain compromise
Impact on administrators
Security and collaboration admins should treat unexpected external Teams support requests as a meaningful attack path. The key risk is not a Teams vulnerability, but users being convinced to override warnings and grant remote access.
Defenders should pay close attention to:
- External Teams chats claiming to be IT support
- Remote-assist sessions followed by cmd.exe or PowerShell activity
- Silent msiexec installs from user sessions
- Portable Node.js execution from user-writable paths
- WinRM connections to servers or identity infrastructure
Recommended next steps
- Review and tighten Teams external collaboration settings where appropriate
- Reinforce user awareness around remote support scams and external tenant warnings
- Hunt for suspicious chains involving Quick Assist/Teams remote control + PowerShell + msiexec
- Monitor for Node.js execution from unusual locations
- Audit and restrict WinRM access to high-value systems
- Use Microsoft’s published hunting and mitigation guidance to update detections and response playbooks
Organizations that rely heavily on Teams and remote support workflows should validate now that collaboration controls, user training, and endpoint detections can disrupt this attack path before it turns into a domain-wide incident.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies