Microsoft warns of Teams-based IT helpdesk impersonation attacks leading to ransomware
Microsoft warns of Teams-based IT impersonation campaign that can lead to ransomware and data theft.
In a blog post, Microsoft said unnamed threat actors reached out to targets at various enterprises through Teams chat while impersonating IT personnel. The attackers pressured victims into granting remote access through screen sharing or remote monitoring and management tools and, once given access, installed malware loaders and other implants.
Microsoft described the malware as just the first stage. Subsequent steps included host reconnaissance, discovery of security products and virtualization, and periodic desktop screen capture, which the company said allowed the attackers to map the network and conduct espionage. The intruders then enumerated domain accounts, servers, and users through native tools and Active Directory Service Interfaces queries before moving laterally.
The final step involved identifying and extracting valuable data, followed by a ransomware infection, Microsoft said. The company did not name the perpetrators, referring to them only as threat actors. According to TechRadar, the fake-IT-support-via-Teams technique has been used by multiple groups, including Russia’s Cozy Bear, FIN7, and Storm-1811. ShinyHunters, an extortion group, is also known to use Teams to trick victims into granting access, but it typically focuses on data exfiltration and rarely deploys an encryptor.
To defend against such campaigns, Microsoft advised enterprises to reinforce user education by establishing internal helpdesk authentication phrases and training employees to recognize external-tenant indicators. The company also urged organizations to verify unsolicited support contacts and to harden Microsoft Teams and email against social engineering. Microsoft recommended using Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge, so malicious messages and URLs are neutralized at the time of click and removed after delivery.