# Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA)

> A global phishing campaign impersonates Microsoft Teams meeting-transcript notifications, redirecting victims to pixel-perfect fake Teams pages that serve a digitally signed MSI installer. The installer deploys a legitimate remote monitoring and management (RMM) tool pre-configured to phone home to attacker-controlled relay servers rather than legitimate infrastructure, using compromised small-business websites and Cloudflare Workers/Pages as resilient, low-cost delivery infrastructure.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1058
- **ID:** TL-2026-1058
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CYFIRMA researchers (report syndicated by Cyber Security News, GBHackers, Cyberpress, and others on 2026-06-24) identified an active, actively-maintained phishing operation that abuses trust in Microsoft Teams meeting workflows. Victims receive an email or chat message spoofing a Teams notification claiming a meeting transcript or recording is ready for download. The link leads to a counterfeit page styled to exactly replicate the real Microsoft Teams web interface. Clicking the download button on the fake page serves a digitally signed Windows MSI installer; because the binary carries a legitimate code-signing certificate, endpoint security tools are substantially less likely to flag it on delivery.

On execution, the MSI installs a genuine, commercially available remote monitoring and management (RMM) tool, but with its configuration silently rewritten to connect the agent to attacker-controlled relay/rendezvous servers instead of the vendor's legitimate cloud service. Because the RMM binary itself is legitimate and signed, this abuse pattern (a 'living-off-trusted-signed-binary' technique) evades both static AV signatures and application-allowlisting policies that trust signed RMM software. The installer's custom-action DLLs (invoked via msiexec/rundll32) additionally establish deep persistence: registration of a Windows service configured for auto-start, a SafeBoot registry entry that lets the payload survive a reboot into Safe Mode with Networking, registration of a malicious Credential Provider DLL that intercepts credentials typed at the Windows logon screen, an LSA Authentication Package registration for further credential harvesting at the OS authentication layer, and COM object registration (CLSID/InprocServer32) to support the credential-provider and persistence chain. The installer/custom-action modules also carry anti-analysis logic: USB-device enumeration and debugger-presence checks to detect sandboxes, and long artificial sleep delays intended to outlast automated dynamic-analysis time budgets.

Infrastructure analysis shows a deliberate dual-hosting strategy: (1) compromised, legitimate small-business websites — cafes, hotels, law firms, medical practices, and schools — are used as landing/relay hosts to inherit domain reputation and evade reputation-based blocking, spanning the US, UK, Brazil, Mexico, Turkey, Malaysia, Tanzania, Russia, and India (with additional targeting reported in Syria); and (2) dedicated, attacker-registered infrastructure using cheap TLDs (.icu, .sbs, .online) plus free, reputable cloud platforms — Cloudflare Workers (*.workers.dev) and Cloudflare Pages (*.pages.dev) — for rapid, disposable, low-cost deployment that is difficult to take down wholesale. Roughly 64% of identified attacker domains use .com TLDs to blend in, with the remainder split across the cheap TLDs above and country-code domains. Temporal analysis of the infrastructure shows 9% under 30 days old, 12% aged 1-3 months, 56% aged 3-6 months (indicating a major campaign expansion beginning approximately March 2026), and 23% older than 6 months — consistent with a long-running, actively maintained operation rather than a single burst campaign.

No CVE is associated with this activity (it relies entirely on social engineering plus abuse of legitimate signed software, not a software vulnerability). No specific threat-actor name, file hashes, C2 IPs/domains, or certificate subject/issuer identities were disclosed by CYFIRMA or any of the syndicating outlets at time of writing; the RMM product/vendor being abused was likewise not named in public reporting. Defenders are advised to prioritize behavior-based detection (new service creation, LSA package/Credential Provider registration changes, unexpected outbound RMM relay traffic) over signature- or reputation-based controls, given the signed nature of the payload and its use of otherwise-legitimate software.

## MITRE ATT&CK

- T1566 Phishing
- T1199 Trusted Relationship
- T1204 User Execution
- T1569 System Services
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1546 Event Triggered Execution
- T1556 Modify Authentication Process
- T1133 External Remote Services
- T1543 Create or Modify System Process
- T1546 Event Triggered Execution
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1556 Modify Authentication Process
- T1497 Virtualization/Sandbox Evasion
- T1218 System Binary Proxy Execution
- T1219 Remote Access Tools
- T1056 Input Capture
- T1556 Modify Authentication Process
- T1120 Peripheral Device Discovery
- T1497 Virtualization/Sandbox Evasion
- T1219 Remote Access Tools
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1090 Proxy
- T1584 Compromise Infrastructure
- T1583 Acquire Infrastructure
- T1586 Compromise Accounts

## Sources

- [Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse](https://cybersecuritynews.com/microsoft-teams-impersonation-campaign-enables-unauthorized-access/)
- [Microsoft Teams-Themed Remote Access Phishing Campaign](https://www.cyfirma.com/research/microsoft-teams-themed-remote-access-phishing-campaign/)
- [Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse](https://www.cryptika.com/microsoft-teams-impersonation-campaign-enables-unauthorized-access-through-rmm-abuse/)
- [Microsoft Teams Phishing Lures Push Victims Toward Remote Access Tool Installation](https://cyberpress.org/teams-phishing-remote-access/)
- [Hackers Use Microsoft Teams-Themed Lures to Deploy Legitimate Remote Access Software](https://gbhackers.com/microsoft-teams-themed-lures/)
- [Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse](https://teamwin.in/microsoft-teams-impersonation-campaign-enables-unauthorized-access-through-rmm-abuse/)
- [Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures](https://www.netskope.com/blog/attackers-weaponize-signed-rmm-tools-via-zoom-meet-teams-lures)
- [Hackers Hide RMM Installs as Fake Chrome Updates and Teams Invites](https://hackread.com/hackers-rmm-installs-fake-chrome-updates-teams-invite/)
- [Phishing Campaigns Weaponise RMM Tools](https://www.cybersecurityintelligence.com/blog/phishing-campaigns-weaponise-rmm-tools-8708.html)
- [Phishing Campaign Exploits RMM Tools to Sustain Unauthorized Remote Access](https://cyberpress.org/phishing-campaign/)
- [Signed malware impersonating workplace apps deploys RMM backdoors](https://www.microsoft.com/en-us/security/blog/2026/03/03/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/)
- [How Phishing Campaigns Abuse Remote Monitoring and Management Tools](https://cyberleveling.com/blog/phishing-campaigns-abuse-rmm-tools-2026)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1058
