logo

Wishing: Webhook Phishing in Teams

ID: da26ba92-8146-5921-82d5-e894715885c9

STIX ID: report--da26ba92-8146-5921-82d5-e894715885c9

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2024-03-14

Date Updated: 2026-04-27

Author: BHIS

...
...

This technical blog explains how default Microsoft Teams features—incoming webhooks (connectors) and per-channel email addresses—can be enumerated and abused to send phishing messages and achieve persistence. It provides step-by-step methods for obtaining and manipulating tokens/cookies, enumerating channels and webhooks, creating webhooks programmatically, and configuring channel emails to accept messages from anyone, with examples using GraphRunner and Burp. The article also outlines detection and mitigation limitations and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.