logo

Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook

ID: e5854ad4-0154-51ce-88fd-87e599bc5474

STIX ID: report--e5854ad4-0154-51ce-88fd-87e599bc5474

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2026-04-18

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

This Microsoft Defender research report describes an observed campaign where adversaries impersonate IT/helpdesk via cross-tenant Microsoft Teams to trick users into granting remote-assist sessions (e.g., Quick Assist). Attackers then perform short interactive reconnaissance, stage payloads using DLL sideloading under trusted signed hosts, establish HTTPS command-and-control, pivot via WinRM to domain resources, deploy management tooling, and exfiltrate targeted business data using Rclone; the report includes detection signatures, advanced-hunting queries, and mitigations (ASR, WDAC, Conditional Access, Safe Links, user education).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.