logo

Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees

ID: e9b991e6-367f-54c8-833d-645698e5798a

STIX ID: report--e9b991e6-367f-54c8-833d-645698e5798a

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-09-01

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Unit 42 observed a coordinated Spring Ring campaign (Jan–Apr 2026) that abused external Microsoft Teams accounts to impersonate IT support, using unsolicited chats that quickly escalated to vishing. Targets were persuaded to run Windows Quick Assist or install RMM tools or a remote-access Trojan, enabling reconnaissance, AMSI bypass attempts, SMB/NTLM activity, and an attempted PetitPotam NTLM relay against domain controllers; the activity affected 150+ employees across at least 10 organizations and was mitigated by Cortex XDR and Unit 42 MDR. Defenders are advised to restrict external Teams communication, enforce callback verification for IT support, monitor SMB/NTLM/relay behavior, and harden NTLM protections such as SMB signing and Extended Protection for Authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.