As organisations increasingly rely on collaboration platforms such as Microsoft Teams, cybercriminals are finding new ways to exploit employee trust rather than technical vulnerabilities.
Researchers have identified a sophisticated phishing campaign in which attackers impersonate internal IT support teams through Microsoft Teams, persuading employees to grant remote access to their devices before deploying malware. By abusing legitimate communication channels and trusted administration tools, the attackers are able to bypass many traditional email and network security controls.
How the Attack Works
The campaign begins with a phishing email, often disguised as an employee survey or another routine business communication. Shortly afterwards, the victim receives a Microsoft Teams message or call from an external account masquerading as the organisation's IT support team.
Using convincing social engineering techniques, the attacker claims they are assisting with a technical issue and instructs the employee to launch legitimate remote administration tools such as:
- AnyDesk
- HopToDesk
- Quick Assist
Once remote access is established, the attacker downloads and installs malicious software, giving them persistent control over the compromised device.
Malware Delivered Through Trusted Tools
Rather than exploiting software vulnerabilities, the attackers rely on legitimate applications that many organisations already trust.
Researchers observed the deployment of EtherRAT, a cross-platform remote access trojan capable of:
- Executing remote commands
- Stealing sensitive information
- Manipulating files
- Maintaining long-term persistence
- Communicating with attacker-controlled infrastructure
Because the initial remote access tools are legitimate, security teams may not immediately recognise malicious activity until after the compromise has occurred.
Why Microsoft Teams Has Become an Attractive Target
Modern enterprises increasingly depend on Microsoft Teams for daily communication with colleagues, customers, and external partners.
Threat actors are exploiting this trust by creating external Teams accounts that closely resemble internal IT support staff. Employees, particularly during busy periods or technical issues, are more likely to comply with requests received through a familiar collaboration platform.
Researchers also note that these attacks often combine multiple social engineering techniques, including:
- Email bombing to overwhelm victims with spam
- Fake IT support calls via Teams
- Requests to install legitimate remote access software
- Malware deployment after remote control is established
This layered approach significantly increases the likelihood of a successful compromise.
Identity Is the Real Target
Although malware is eventually installed, the primary objective is often identity compromise.
Once attackers gain access to an endpoint, they can harvest authentication tokens, browser sessions, credentials, and privileged access that enable them to move laterally across the organisation.
This highlights a broader shift in cyberattacks, where identity—not infrastructure—is becoming the primary attack surface. Compromised identities allow attackers to bypass perimeter defences and operate as legitimate users within enterprise environments.
Strengthening Defences Against Collaboration-Based Attacks
Organisations can reduce their exposure by combining technical controls with user awareness.
Key recommendations include:
Restrict External Collaboration
Limit Microsoft Teams communication with unknown external tenants and enable clear warnings for external users.
Verify IT Requests
Employees should confirm unexpected support requests through trusted internal channels before granting remote access.
Control Remote Administration Tools
Restrict the use of remote access applications and monitor for unauthorised installations or unusual usage.
Monitor Identity Activity
Implement continuous monitoring for suspicious authentication events, remote sessions, and privileged access requests.
Strengthen User Awareness
Regular phishing simulations and security awareness training help employees recognise impersonation attempts across collaboration platforms, not just email.
Trevonix Perspective
At Trevonix, we see campaigns like this as evidence that identity attacks are evolving beyond traditional phishing emails.
Collaboration platforms such as Microsoft Teams have become integral to enterprise operations, making them attractive targets for attackers seeking to exploit human trust. As these attacks increasingly combine social engineering, legitimate administration tools, and identity compromise, organisations need a security strategy that extends beyond endpoint protection.
Identity-first security, Zero Trust access, continuous authentication, privileged access management, and identity threat detection and response (ITDR) are becoming essential to detecting and stopping these modern attack chains before they result in business disruption.
As enterprises continue embracing cloud collaboration and AI-powered workplaces, protecting identities across every communication channel will remain critical to cyber resilience.
Key Takeaways
- Attackers are abusing Microsoft Teams to impersonate IT support personnel.
- Victims are persuaded to install legitimate remote access tools before malware is deployed.
- EtherRAT provides attackers with persistent remote control over compromised systems.
- Collaboration platforms are becoming increasingly popular entry points for identity-based attacks.
- Organisations should strengthen identity security, remote access controls, and user awareness to defend against evolving social engineering campaigns.
Reference
GBHackers – https://gbhackers.com/microsoft-teams-abused-2/


