Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA) — Threadlinqs Intelligence
As of 2026-07-02, Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA) is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1058 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
A global phishing campaign impersonates Microsoft Teams meeting-transcript notifications, redirecting victims to pixel-perfect fake Teams pages that serve a digitally signed MSI installer. The
CYFIRMA researchers (report syndicated by Cyber Security News, GBHackers, Cyberpress, and others on 2026-06-24) identified an active, actively-maintained phishing operation that abuses trust in Microsoft Teams meeting workflows. Victims receive an email or chat message spoofing a Teams notification claiming a meeting transcript or recording is ready for download. The link leads to a counterfeit page styled to exactly replicate the real Microsoft Teams web interface. Clicking the download button on the fake page serves a digitally signed Windows MSI installer; because the binary carries a legitimate code-signing certificate, endpoint security tools are substantially less likely to flag it on delivery.
On execution, the MSI installs a genuine, commercially available remote monitoring and management (RMM) tool, but with its configuration silently rewritten to connect the agent to attacker-controlled relay/rendezvous servers instead of the vendor's legitimate cloud service. Because the RMM binary itself is legitimate and signed, this abuse pattern (a 'living-off-trusted-signed-binary' technique) evades both static AV signatures and application-allowlisting policies that trust signed RMM software. The installer's custom-action DLLs (invoked via msiexec/rundll32) additionally establish deep persistence: registration of a Windows service configured for auto-start, a SafeBoot registry entry that lets the payload survive a reboot into Safe Mode with Networking, registration of a malicious Credential Provider DLL that intercepts credentials typed at the Windows logon screen, an LSA Authentication Package registration for further credential harvesting at the OS authentication layer, and COM object registration (CLSID/InprocServer32) to support the credential-provider and persistence chain. The installer/custom-action modules also carry anti-analysis logic: USB-device enumeration and debugger-presence checks to detect sandboxes, and long artificial sleep delays intended to outlast automated dynamic-analysis time budgets.
Infrastructure analysis shows a deliberate dual-hosting strategy: (1) compromised, legitimate small-business websites — cafes, hotels, law firms, medical practices, and schools — are used as landing/relay hosts to inherit domain reputation and evade reputation-based blocking, spanning the US, UK, Brazil, Mexico, Turkey, Malaysia, Tanzania, Russia, and India (with additional targeting reported in Syria); and (2) dedicated, attacker-registered infrastructure using cheap TLDs (.icu, .sbs, .online) plus free, reputable cloud platforms — Cloudflare Workers (*.workers.dev) and Cloudflare Pages (*.pages.dev) — for rapid, disposable, low-cost deployment that is difficult to take down wholesale. Roughly 64% of identified attacker domains use .com TLDs to blend in, with the remainder split across the cheap TLDs above and country-code domains. Temporal analysis of the infrastructure shows 9% under 30 days old, 12% aged 1-3 months, 56% aged 3-6 months (indicating a major campaign expansion beginning approximately March 2026), and 23% older than 6 months — consistent with a long-running, actively maintained operation rather than a single burst campaign.
No CVE is associated with this activity (it relies entirely on social engineering plus abuse of legitimate signed software, not a software vulnerability). No specific threat-actor name, file hashes, C2 IPs/domains, or certificate subject/issuer identities were disclosed by CYFIRMA or any of the syndicating outlets at time of writing; the RMM product/vendor being abused was likewise not named in public reporting. Defenders are advised to prioritize behavior-based detection (new service creation, LSA package/Credential Provider registration changes, unexpected outbound RMM relay traffic) over signature- or reputation-based controls, given the signed nature of the payload and its use of otherwise-legitimate software.
Weaknesses (CWE)
CWE-506, CWE-451, CWE-522
Target sectors: hospitality, legal, health, education, smallbusiness, cross-sector
Target regions: united states of america, united kingdom, brazil, mexico, turkey, malaysia, tanzania, russia, india, syria
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1566, T1199, T1204, T1569, T1543, T1547, T1546, T1556, T1133, T1543