Threat reportPhishingTL-2026-1058

Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA)

mediumACTIVE

Microsoft Teams Impersonation Phishing Campaign Deploys (TL-2026-1058), also tracked as Microsoft Teams-Themed Remote Access Phishing Campaign, is a medium-severity phishing campaign, first published 2026-07-02. It has no confirmed attribution, affects Microsoft Microsoft Teams (brand impersonated, not itself vulnerable), maps to 22 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 19 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-1058

Threat ID
TL-2026-1058
Also known as
Microsoft Teams-Themed Remote Access Phishing Campaign
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
hospitality, legal, health, education, smallbusiness, cross-sector
Target regions
united states of america, united kingdom, brazil, mexico, turkey, malaysia, tanzania, russia, india, syria
Detection rules
9
Indicators of compromise
19

How Microsoft Teams Impersonation Phishing Campaign Deploys works

A global phishing campaign impersonates Microsoft Teams meeting-transcript notifications, redirecting victims to pixel-perfect fake Teams pages that serve a digitally signed MSI installer. The installer deploys a legitimate remote monitoring and management (RMM) tool pre-configured to phone home to attacker-controlled relay servers rather than legitimate infrastructure, using compromised small-business websites and Cloudflare Workers/Pages as resilient, low-cost delivery infrastructure.

CYFIRMA researchers (report syndicated by Cyber Security News, GBHackers, Cyberpress, and others on 2026-06-24) identified an active, actively-maintained phishing operation that abuses trust in Microsoft Teams meeting workflows. Victims receive an email or chat message spoofing a Teams notification claiming a meeting transcript or recording is ready for download. The link leads to a counterfeit page styled to exactly replicate the real Microsoft Teams web interface. Clicking the download button on the fake page serves a digitally signed Windows MSI installer; because the binary carries a legitimate code-signing certificate, endpoint security tools are substantially less likely to flag it on delivery.

On execution, the MSI installs a genuine, commercially available remote monitoring and management (RMM) tool, but with its configuration silently rewritten to connect the agent to attacker-controlled relay/rendezvous servers instead of the vendor's legitimate cloud service. Because the RMM binary itself is legitimate and signed, this abuse pattern (a 'living-off-trusted-signed-binary' technique) evades both static AV signatures and application-allowlisting policies that trust signed RMM software. The installer's custom-action DLLs (invoked via msiexec/rundll32) additionally establish deep persistence: registration of a Windows service configured for auto-start, a SafeBoot registry entry that lets the payload survive a reboot into Safe Mode with Networking, registration of a malicious Credential Provider DLL that intercepts credentials typed at the Windows logon screen, an LSA Authentication Package registration for further credential harvesting at the OS authentication layer, and COM object registration (CLSID/InprocServer32) to support the credential-provider and persistence chain. The installer/custom-action modules also carry anti-analysis logic: USB-device enumeration and debugger-presence checks to detect sandboxes, and long artificial sleep delays intended to outlast automated dynamic-analysis time budgets.

Infrastructure analysis shows a deliberate dual-hosting strategy: (1) compromised, legitimate small-business websites — cafes, hotels, law firms, medical practices, and schools — are used as landing/relay hosts to inherit domain reputation and evade reputation-based blocking, spanning the US, UK, Brazil, Mexico, Turkey, Malaysia, Tanzania, Russia, and India (with additional targeting reported in Syria); and (2) dedicated, attacker-registered infrastructure using cheap TLDs (.icu, .sbs, .online) plus free, reputable cloud platforms — Cloudflare Workers (*.workers.dev) and Cloudflare Pages (*.pages.dev) — for rapid, disposable, low-cost deployment that is difficult to take down wholesale. Roughly 64% of identified attacker domains use .com TLDs to blend in, with the remainder split across the cheap TLDs above and country-code domains. Temporal analysis of the infrastructure shows 9% under 30 days old, 12% aged 1-3 months, 56% aged 3-6 months (indicating a major campaign expansion beginning approximately March 2026), and 23% older than 6 months — consistent with a long-running, actively maintained operation rather than a single burst campaign.

No CVE is associated with this activity (it relies entirely on social engineering plus abuse of legitimate signed software, not a software vulnerability). No specific threat-actor name, file hashes, C2 IPs/domains, or certificate subject/issuer identities were disclosed by CYFIRMA or any of the syndicating outlets at time of writing; the RMM product/vendor being abused was likewise not named in public reporting. Defenders are advised to prioritize behavior-based detection (new service creation, LSA package/Credential Provider registration changes, unexpected outbound RMM relay traffic) over signature- or reputation-based controls, given the signed nature of the payload and its use of otherwise-legitimate software.

MITRE ATT&CK techniques used in TL-2026-1058

Defense Evasion

T1036 Masquerading; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow

Credential Access

T1056 Input Capture; T1556 Modify Authentication Process

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Discovery

T1120 Peripheral Device Discovery; T1497 Virtualization/Sandbox Evasion

Persistence

T1133 External Remote Services; T1543 Create or Modify System Process; T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution; T1556 Modify Authentication Process

Initial Access

T1199 Trusted Relationship; T1566 Phishing

Execution

T1204 User Execution; T1569 System Services

command-and-control

T1219 Remote Access Tools

Privilege Escalation

T1543 Create or Modify System Process; T1546 Event Triggered Execution

defense-impairment

T1556 Modify Authentication Process

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1586 Compromise Accounts

Affected products and versions in Microsoft Teams Impersonation Phishing Campaign Deploys

  • Microsoft — Microsoft Teams (brand impersonated, not itself vulnerable)
    Vulnerable versions: N/A - social engineering lure, not a Teams product vulnerability
  • Various — Unnamed commercial RMM (remote monitoring and management) software
    Vulnerable versions: Legitimate signed installer, abused via malicious configuration
  • Microsoft — Windows (persistence/credential-theft mechanisms: Service Control Manager, LSA, Credential Provider, SafeBoot)
    Vulnerable versions: All supported Windows versions supporting services/LSA packages/credential providers

Remediation for Microsoft Teams Impersonation Phishing Campaign Deploys

Immediate actions

  • Block or quarantine unsolicited 'Teams meeting transcript/recording ready' emails and chat lures at the email/collaboration gateway
  • Enforce administrator-only software installation policy to prevent end users from running unsolicited MSI installers
  • Block outbound traffic to .icu, .sbs, and .online TLDs by default and alert on any hits from endpoints
  • Alert on and investigate any new outbound connections from newly installed RMM/remote-access software to unfamiliar relay endpoints
  • Enforce multi-factor authentication organization-wide to blunt credential theft from the malicious Credential Provider/LSA package
  • For any host confirmed to have run the installer: perform full forensic review, reset all credentials used on that host, and rebuild rather than clean

Workarounds

  • Disable or restrict end-user ability to install MSI packages without administrative approval
  • Restrict which RMM tools are permitted to run in the environment via application control, denying unapproved RMM binaries even if code-signed

Longer-term hardening

  • Deploy behavior-based EDR detections for new Windows service creation, LSA Authentication Package registration, and Credential Provider CLSID/InprocServer32 registration rather than relying on signature or reputation checks
  • Implement application control / allowlisting that accounts for RMM tools being trusted-but-abusable, e.g. alerting on RMM software installed outside of IT-managed deployment channels
  • Monitor DNS/proxy logs for connections to Cloudflare Workers (*.workers.dev) and Cloudflare Pages (*.pages.dev) subdomains that are not part of approved SaaS usage
  • User awareness training specifically covering fake Microsoft Teams 'transcript ready' / 'recording ready' lures
  • Periodic auditing of small-business/partner websites in the supply chain for signs of compromise being used as phishing relay infrastructure

Weaknesses (CWE) in Microsoft Teams Impersonation Phishing Campaign Deploys

CWE-506, CWE-451, CWE-522

Timeline of Microsoft Teams Impersonation Phishing Campaign Deploys

  • CYFIRMA infrastructure-age analysis indicates a major expansion phase of campaign domains/hosting began around this time (56% of identified infrastructure dated 3-6 months old as of the June 2026 report).
  • Microsoft Security Blog publishes related research on signed malware impersonating workplace collaboration apps to deploy RMM backdoors, establishing the broader trend this campaign belongs to.
  • Hackread reports on threat actors disguising RMM installs as fake Chrome updates and Teams meeting invites.
  • Netskope publishes related research on attackers weaponizing signed RMM tools via Zoom, Google Meet, and Microsoft Teams-themed lures, describing a broader pattern consistent with the CYFIRMA findings.
  • Cyberpress and CyberSecurityIntelligence publish coverage on phishing campaigns broadly weaponizing RMM tools for sustained unauthorized remote access.
  • Cyber Security News, GBHackers, Cryptika, Teamwin, and Cyberpress syndicate/report on the CYFIRMA findings, broadening public awareness of the campaign.
  • CYFIRMA publishes 'Microsoft Teams-Themed Remote Access Phishing Campaign' research detailing the fake-Teams-page delivery chain, signed RMM installer, persistence mechanisms, and global compromised-site/Cloudflare infrastructure.
  • Threadlinqs Intelligence Platform ingests and researches the campaign via RSS hunt pipeline for TL-2026-1058.

Sources cited for Microsoft Teams Impersonation Phishing Campaign Deploys

Detection coverage for TL-2026-1058

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1058 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats