Security

Microsoft Teams IT Support Scam Enables Enterprise Access

3 min read

Summary

Microsoft Threat Intelligence detailed a human-operated attack that abuses Microsoft Teams external collaboration to impersonate IT support and trick users into granting remote access. Once inside, attackers use legitimate tools like PowerShell, MSI installers, Node.js, and WinRM to establish persistence, conduct reconnaissance, and move laterally toward high-value systems such as domain controllers.

Need help with Security?Talk to an Expert

Microsoft Teams IT Support Scam Enables Enterprise Access

Introduction

Microsoft has published new threat intelligence on a high-impact social engineering campaign that starts in Microsoft Teams and can end with enterprise-wide compromise. For IT and security teams, this matters because the attack relies on legitimate collaboration and admin tools, making it harder to distinguish from normal support activity.

What’s happening

Attackers are impersonating IT or helpdesk staff through Microsoft Teams external chats or calls. The goal is to persuade a user to approve a remote support session, such as a Teams screen-share control request or a Quick Assist connection.

Once access is granted, the campaign quickly escalates:

  • PowerShell downloads a malicious MSI from cloud storage
  • The MSI silently installs a loader and encrypted JavaScript implant
  • If needed, the attacker fetches a portable Node.js runtime to execute the implant
  • The malware uses HTTPS polling for command-and-control
  • Operators perform host, security product, and Active Directory reconnaissance
  • Additional payloads may run through trusted binaries like rundll32
  • Lateral movement occurs over WinRM (TCP 5985) toward systems like domain controllers and certificate authorities

Why this is significant

This is not a typical phishing attack that stops at credential theft. Microsoft describes it as a hands-on-keyboard intrusion that gives an external operator interactive, credential-backed access inside the environment.

Because the activity uses trusted tools—Teams, remote support software, Windows Installer, PowerShell, Node.js, and native Windows admin protocols—it can blend into expected enterprise operations. That raises the risk of:

  • Privilege escalation
  • Data theft
  • Security control tampering
  • Ransomware deployment
  • Broader domain compromise

Impact on administrators

Security and collaboration admins should treat unexpected external Teams support requests as a meaningful attack path. The key risk is not a Teams vulnerability, but users being convinced to override warnings and grant remote access.

Defenders should pay close attention to:

  • External Teams chats claiming to be IT support
  • Remote-assist sessions followed by cmd.exe or PowerShell activity
  • Silent msiexec installs from user sessions
  • Portable Node.js execution from user-writable paths
  • WinRM connections to servers or identity infrastructure
  • Review and tighten Teams external collaboration settings where appropriate
  • Reinforce user awareness around remote support scams and external tenant warnings
  • Hunt for suspicious chains involving Quick Assist/Teams remote control + PowerShell + msiexec
  • Monitor for Node.js execution from unusual locations
  • Audit and restrict WinRM access to high-value systems
  • Use Microsoft’s published hunting and mitigation guidance to update detections and response playbooks

Organizations that rely heavily on Teams and remote support workflows should validate now that collaboration controls, user training, and endpoint detections can disrupt this attack path before it turns into a domain-wide incident.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft Teamssocial engineeringremote accessWinRMthreat intelligence

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.