Cybercriminals are increasingly using Microsoft Teamsto deploy malware and seize control of victims' systems (taking advantage of the platform's trusted role in corporate communications).

In a sophisticated campaign, malicious actors communicate with targets via Microsoft Teams messages and pose as IT support staff. Their goal is to trick employees into granting remote access. This is a dangerous evolution from traditional email phishing attacks and is becoming more common.
Social engineering remains a highly effective tactic for hackers, and as businesses have integrated platforms like Microsoft Teams into their core operations, attackers are following suit. Employees’ inherent trust in internal messaging makes it fertile ground for deception.
Recent campaigns analyzed by Permiso cybersecurity researchers reveal a multi-layered attack that begins with a simple message and culminates in the deployment of powerful, multi-functional malware.
See also: PromptLock: The first AI-powered ransomware
Microsoft Teams Abuse: Attack Chain
The attack chain often begins with a direct message or call from a new or compromised Microsoft Teams account. These accounts are designed to appear legitimate, using names like “IT SUPPORT ✅” or “Help Specialist” to impersonate trusted personnel. Attackers often use checkmark emojis to simulate a verified status and exploit Microsoft’s onmicrosoft.com domain structure to appear as if they are part of the organization.
By posing as IT staff dealing with a routine issue such as system maintenance, attackers build trust with their target. Once trust is established, they convince the employee to install remote access software, such as QuickAssist or AnyDesk, under the guise of providing technical assistance. This critical step gives the attacker direct access to the user’s computer and the corporate network.
See also: 28,000+ Citrix instances vulnerable to zero-day vulnerability

While similar techniques, involving remote access tools, have been linked to ransomware groups such as BlackBasta, these newer campaigns are more direct, often bypassing the preliminary mass email campaigns seen in the past. Malicious payloads have also diversified, with recent incidents including the DarkGate and Matanbuchus malware loaders.
Once remote access is secured, the attacker executes a PowerShell command to download the main malicious payload. This script is equipped with credential theft, long-term persistence, and remote code execution capabilities . To evade detection and make removal difficult, the malware can designate its own process as “critical,” which would cause the system to crash if terminated. It also uses a legitimate-looking Windows prompt to trick users into entering passwords their , which are then exported to a server controlled by the attacker.
Analysis of the payload code revealed embedded encryption keys that link the campaign to a group monitored as Water Gamayun (also known as EncryptHub). This group has a history of combining sophisticated social engineering with custom malware to target English-speaking IT professionals and developers.
See also: Warning: Hackers Attack FreePBX Servers
Employees should be trained to remain vigilant against unsolicited communication, even on trusted internal platforms. All requests for credentials or installation of remote access software should be independently verified through a known, separate communication channel.

Breach indicators based on the information provided
| Indicator | Type |
|---|---|
https://audiorealteak[.]com/payload/build.ps1 | URL |
https://cjhsbam[.]com/payload/runner.ps1 | URL |
104.21.40[.]219 | IPv4 |
193.5.65[.]199 | IPv4 |
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) AppleWebKit/534.6 (KHTML, like Gecko) Chrome/7.0.500.0 Safari/534.6 | User Agent (UA) |
&9*zS7LY%ZN1thfI | Initialization Vector |
123456789012345678901234r0hollah | Encryption Key |
62088a7b-ae9f-2333-77a-6e9c921cb48e | Mutex |
Help Desk Specialist | User Display Name |
IT SUPPORT | User Display Name |
Marco DaSilva IT Support | User Display Name |
IT SUPPORT | User Display Name |
Help Desk | User Display Name |
@cybersecurityadm.onmicrosoft[.]com | User Principal Name |
@updateteamis.onmicrosoft[.]com | User Principal Name |
@supportbotit.onmicrosoft[.]com | User Principal Name |
@replysupport.onmicrosoft[.]com | User Principal Name |
@administratoritdep.onmicrosoft[.]com | User Principal Name |
@luxadmln.onmicrosoft[.]com | User Principal Name |
@firewalloverview.onmicrosoft[.]com | User Principal Name |
As malicious actors continue to innovate, a defense-in-depth strategy, combining technical controls with strong user education, is essential to protect against attacks that turn collaboration tools into conduits for breaches.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
