Microsoft Teams Exploited for Silent Enterprise Takeovers
ID: 0307acc2-6a10-5d88-bf79-4f4a9d9cfe63
STIX ID: report--0307acc2-6a10-5d88-bf79-4f4a9d9cfe63
Feed Name: securityonline.info
Threat Score
Microsoft Defender Security Research Team describes a sophisticated intrusion campaign that exploits cross-tenant Microsoft Teams social engineering to impersonate IT support and obtain remote assistance, then uses legitimate administrative tools and protocols (vendor-signed binaries, WinRM, Level RMM via msiexec) to move laterally and maintain persistence before exfiltrating sensitive documents with Rclone using selective file-type exclusions to reduce detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
