IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools
Date:
Thu, 03 Sep 2026 16:55:00 +0000
Description:
Microsoft is warning about an ongoing scam campaign starting in Teams.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft warns of Teamsbased campaign where attackers impersonate IT staff Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.
In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a Teams chat , while impersonating IT staff. They were coercing their victims into granting remote access via screen sharing or remote monitoring and management tools and once received, used their access
to install malware loaders and various other implants. Latest Videos From TechRadar Watch full video here: How to defend against Teams-borne phishing The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and periodic desktop screen capture. In other words - mapping out the landscape and conducting espionage.
The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally. You may like Microsoft login pages are being abused as hackers try and lure in unlucky victims The enemy within: how to stop a
simple Teams message taking down your business New malware targets Microsoft Teams users by posing as your company's IT helpdesk
The final step includes identifying and extracting valuable data, followed by a ransomware infection.
Microsoft does not name the perpetrators, and mostly refers to them as threat actors. It makes sense, since the fake IT support via Teams technique is
being used by multiple groups at this moment. Russias Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples. Are you a pro? Subscribe
to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
The worlds biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.
Whoever the attackers are, and whoever theyre after, one thing is for certain - the risk in the enterprise environment has never been greater.
That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.
The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed
after delivery, Microsoft urges. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/it-helpdesk-impersonation-hits-microsof t-teams-once-again-with-the-hackers-hiding-their-activity-within-legitimate-to ols
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)