HomeSecurityAbuse of Microsoft Teams for remote access

Abuse of Microsoft Teams for remote access

Cybercriminals are increasingly using Microsoft Teamsto deploy malware and seize control of victims' systems (taking advantage of the platform's trusted role in corporate communications).

Microsoft Teams remote access

In a sophisticated campaign, malicious actors communicate with targets via Microsoft Teams messages and pose as IT support staff. Their goal is to trick employees into granting remote access. This is a dangerous evolution from traditional email phishing attacks and is becoming more common.

Social engineering remains a highly effective tactic for hackers, and as businesses have integrated platforms like Microsoft Teams into their core operations, attackers are following suit. Employees’ inherent trust in internal messaging makes it fertile ground for deception.

Recent campaigns analyzed by Permiso cybersecurity researchers reveal a multi-layered attack that begins with a simple message and culminates in the deployment of powerful, multi-functional malware.

See also: PromptLock: The first AI-powered ransomware

Microsoft Teams Abuse: Attack Chain

The attack chain often begins with a direct message or call from a new or compromised Microsoft Teams account. These accounts are designed to appear legitimate, using names like “IT SUPPORT ✅” or “Help Specialist” to impersonate trusted personnel. Attackers often use checkmark emojis to simulate a verified status and exploit Microsoft’s onmicrosoft.com domain structure to appear as if they are part of the organization.

By posing as IT staff dealing with a routine issue such as system maintenance, attackers build trust with their target. Once trust is established, they convince the employee to install remote access software, such as QuickAssist or AnyDesk, under the guise of providing technical assistance. This critical step gives the attacker direct access to the user’s computer and the corporate network.

See also: 28,000+ Citrix instances vulnerable to zero-day vulnerability

Abuse of Microsoft Teams for remote access

While similar techniques, involving remote access tools, have been linked to ransomware groups such as BlackBasta, these newer campaigns are more direct, often bypassing the preliminary mass email campaigns seen in the past. Malicious payloads have also diversified, with recent incidents including the DarkGate and Matanbuchus malware loaders.

Once remote access is secured, the attacker executes a PowerShell command to download the main malicious payload. This script is equipped with credential theft, long-term persistence, and remote code execution capabilities . To evade detection and make removal difficult, the malware can designate its own process as “critical,” which would cause the system to crash if terminated. It also uses a legitimate-looking Windows prompt to trick users into entering passwords their , which are then exported to a server controlled by the attacker.

Analysis of the payload code revealed embedded encryption keys that link the campaign to a group monitored as Water Gamayun (also known as EncryptHub). This group has a history of combining sophisticated social engineering with custom malware to target English-speaking IT professionals and developers.

See also: Warning: Hackers Attack FreePBX Servers

Employees should be trained to remain vigilant against unsolicited communication, even on trusted internal platforms. All requests for credentials or installation of remote access software should be independently verified through a known, separate communication channel.

Abuse of Microsoft Teams for remote access

Breach indicators based on the information provided

IndicatorType
https://audiorealteak[.]com/payload/build.ps1URL
https://cjhsbam[.]com/payload/runner.ps1URL
104.21.40[.]219IPv4
193.5.65[.]199IPv4
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) AppleWebKit/534.6 (KHTML, like Gecko) Chrome/7.0.500.0 Safari/534.6User Agent (UA)
&9*zS7LY%ZN1thfIInitialization Vector
123456789012345678901234r0hollahEncryption Key
62088a7b-ae9f-2333-77a-6e9c921cb48eMutex
Help Desk Specialist User Display Name
IT SUPPORTUser Display Name
Marco DaSilva IT Support User Display Name
IT SUPPORT User Display Name
Help DeskUser Display Name
@cybersecurityadm.onmicrosoft[.]comUser Principal Name
@updateteamis.onmicrosoft[.]comUser Principal Name
@supportbotit.onmicrosoft[.]comUser Principal Name
@replysupport.onmicrosoft[.]comUser Principal Name
@administratoritdep.onmicrosoft[.]comUser Principal Name
@luxadmln.onmicrosoft[.]comUser Principal Name
@firewalloverview.onmicrosoft[.]comUser Principal Name

As malicious actors continue to innovate, a defense-in-depth strategy, combining technical controls with strong user education, is essential to protect against attacks that turn collaboration tools into conduits for breaches.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS