IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools
Microsoft is warning about an ongoing scam campaign starting in Teams.
Microsoft warns of a hacking campaign targeting Microsoft Teams, where attackers impersonate IT support staff. Victims receive a Teams message, leading them to grant remote access, which enables the hackers to install malware and gain access to sensitive data. The attackers map out the victim's network, enumerate domain accounts, servers, and users, and move laterally within the system.
The final stage involves identifying and extracting valuable data, followed by a ransomware infection. The attackers have been linked to various groups, including Russia's Cozy Bear, FIN7, Storm-1811, and ShinyHunters. Microsoft advises enterprises to reinforce user education, verify unsolicited support contact, and harden Microsoft Teams and email against social engineering.
They recommend using Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) to neutralize malicious messages and URLs at the time of delivery.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.