Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook
ID: e5854ad4-0154-51ce-88fd-87e599bc5474
STIX ID: report--e5854ad4-0154-51ce-88fd-87e599bc5474
Feed Name: Microsoft Security
Date Published: 2026-04-18
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
This Microsoft Defender research report describes an observed campaign where adversaries impersonate IT/helpdesk via cross-tenant Microsoft Teams to trick users into granting remote-assist sessions (e.g., Quick Assist). Attackers then perform short interactive reconnaissance, stage payloads using DLL sideloading under trusted signed hosts, establish HTTPS command-and-control, pivot via WinRM to domain resources, deploy management tooling, and exfiltrate targeted business data using Rclone; the report includes detection signatures, advanced-hunting queries, and mitigations (ASR, WDAC, Conditional Access, Safe Links, user education).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
