Undermining Microsoft Teams Security by Mining Tokens by Connor Peoples
ID: 8fd37737-9592-5cad-9629-bec6ace03300
STIX ID: report--8fd37737-9592-5cad-9629-bec6ace03300
Feed Name: Vectra AI Blog
Vectra discovered that Microsoft Teams desktop clients (Windows, macOS, Linux) store active access tokens in plaintext within local files (Cookies and leveldb). An attacker with read access to these files can extract tokens to impersonate users, bypass MFA, and access M365 services (Teams, Outlook, SharePoint) via the client or Graph API. The report documents extraction and abuse techniques, demonstrates a proof-of-concept tool that reads the SQLite cookie DB and sends a message containing a stolen token, and recommends baselining ACLs, monitoring file access to specific Teams storage paths, using the web client, and storing tokens securely (e.g., keytar or OS-protected stores).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
