logo

Microsoft: Teams increasingly abused in helpdesk impersonation attacks

ID: 397542cd-0acb-5ea5-aa82-4edc0ea47590

STIX ID: report--397542cd-0acb-5ea5-aa82-4edc0ea47590

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft warns that attackers are increasingly abusing external Microsoft Teams collaboration to impersonate IT/helpdesk personnel and trick employees into granting remote assistance (e.g., Quick Assist). Attackers use that access to run reconnaissance, drop payloads in writable locations, execute via DLL side‑loading, blend C2 over HTTPS into normal traffic, move laterally using WinRM, deploy additional remote management tools, and exfiltrate filtered valuable data to external cloud storage (often using Rclone); Microsoft recommends treating external Teams contacts as untrusted and restricting/monitoring remote assistance and WinRM usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.