Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access
Microsoft Teams Phishing (TL-2026-2129) is a medium-severity phishing campaign, first published 2026-08-24. It has no confirmed attribution, affects Microsoft Microsoft Teams, maps to 18 MITRE ATT&CK techniques (T1059.010, T1102.001, T1176), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-2129
- Threat ID
- TL-2026-2129
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-24
- Last reviewed
- 2026-08-24
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Microsoft Teams Phishing
Malware and tooling: AnyDesk, EtherRAT, SNOWBASIN, SNOWBELT, SNOWGLAZE, AnyDesk, Burp Suite, DWAgent, HopToDesk, Microsoft Quick Assist, Quick Assist
Threat actors abuse Microsoft Teams' default external-collaboration settings to impersonate IT helpdesk staff via one-on-one chat, unbannered vishing calls, and screen-share requests, then deliver files through Burp Suite-manipulated SharePoint links and install RMM tools (Quick Assist, AnyDesk, DWAgent) for persistent remote access.
How Microsoft Teams Phishing works
Team AXON (Hunters) documents an initial-access technique class in which external actors exploit Microsoft Teams' default "external organizations communication" setting, which lets senders outside a Microsoft 365 tenant message and call organizational users without prior vetting. Attackers stand up new or compromised Entra ID tenants (commonly on the default *.onmicrosoft.com subdomain, often domains registered shortly before use), enumerate valid targets through Teams' built-in external-user email search, and then make first contact impersonating IT/helpdesk personnel, in some cases preceded by an email-bombing burst to manufacture a plausible pretext for a support call. Contact happens through one-on-one chat with spoofed display names such as "Help Desk," through voice-phishing (vishing) calls that Teams allows an unvetted external sender to place with no warning pop-up on the victim's side (unlike chat, where an "(External)" tag is shown, and which attackers further obscure by inserting non-ASCII/emoji characters), or through meeting invitations where the external-sender warning is not consistently enforced once the victim answers.
Because the Teams client does not allow file attachments to be sent to external one-on-one chats through the GUI, attackers use an intercepting proxy (Burp Suite) to modify the underlying HTTP request and inject a SharePoint file-sharing link directly into the chat message, bypassing the restriction. Because the link points at a SharePoint object rather than an inline attachment, the attacker can swap the file's contents after the link has already been delivered and trusted by the victim. Once initial trust is established -- often reinforced by a live screen-sharing session that Teams permits by default -- the victim is walked through installing a legitimate remote-monitoring-and-management (RMM) tool (Quick Assist, AnyDesk, or DWAgent), giving the attacker hands-on-keyboard remote access to the endpoint that persists after the call ends.
Hunters explicitly frames this as a fast-rising, actively evolving technique class rather than a single incident, citing their own November 2024 VEILDrive research (Sangria Tempest / Storm-1674 abusing Teams, SharePoint, Quick Assist, and OneDrive as C2 against a U.S. critical-infrastructure target) as the precedent that established Teams-based initial access as repeatable tradecraft. That framing is corroborated by a wave of independently-attributed campaigns using the same helpdesk-impersonation-via-Teams pretext but different tooling: Microsoft's own October 2025 advisory names Storm-1811, Octo Tempest, Midnight Blizzard, Void Blizzard, Sangria Tempest, Storm-1674, and Peach Sandstorm as actors abusing Teams for initial access, delivery, or credential capture; Storm-1811 specifically pairs this pretext with Quick Assist to deliver Black Basta ransomware; and later, unrelated campaigns (UNC6692's SNOWBELT/SNOWBASIN/SNOWGLAZE malware suite reported April 2026, and an EtherRAT-via-HopToDesk/AnyDesk campaign reported July 2026) show the same Teams helpdesk-impersonation pretext still being used by different, separately-attributed actors well into 2026. The Hunters source itself provides no threat-actor attribution, malware family, or network IOC for the specific campaign it documents -- its contribution is the initial-access/delivery tradecraft and the M365 unified-audit-log detection methodology (ChatCreated, MessageSent, UserAccepted, TeamsImpersonationDetected, and TIMailData events) used to hunt for it.
Three later, independently-attributed campaigns fill in the technical follow-on detail this class of attack produces once trust is established. Palo Alto Networks Unit 42 (June 2026) retrospectively attributes the earliest confirmed nation-state use of this exact pretext to Cloaked Ursa (APT29 / Midnight Blizzard), which operationalized Teams-based helpdesk impersonation in late 2024 using compromised partner/vendor accounts to send credential-harvesting links to spoofed Microsoft login portals, paired with MFA-approval-request manipulation to complete the account takeover once a password was captured. Mandiant's UNC6692 cluster (active December 2025, reported April 2026) impersonates IT helpdesk staff via an email-bombing burst followed by a Teams chat offering a fake "Mailbox Repair and Sync Utility v2.1.5"; the link downloads an AutoHotkey loader script from an attacker-controlled AWS S3 bucket. The script runs a gatekeeper routine to restrict execution to intended targets and evade automated sandboxes, then launches Microsoft Edge headless with the `--load-extension` flag to silently install a malicious Chromium extension named SNOWBELT, whose fake "Health Check" button re-prompts the victim for mailbox credentials. The same loader deploys the SNOWBELT JavaScript backdoor and the SNOWBASIN persistent backdoor (a local HTTP listener on ports 8000-8002 supporting remote command execution, screenshotting, and file operations), tunneled out via the SNOWGLAZE Python WebSocket relay. Finally, a July 2026 campaign reported by Unit 42's Brian Janower (via The Register) reuses the identical fake-IT-support-over-Teams pretext, this time walking victims through installing HopToDesk or AnyDesk to deliver EtherRAT, a cross-platform (Windows/Linux/macOS) Node.js RAT that resolves its C2 server address from an Ethereum smart contract ("EtherHiding"-style blockchain dead-drop resolution) with conventional domains as fallback; Teams itself leaves a forensic artifact of the abused screen-control session in files prefixed `CtrlVirtualCursorWin_*`.
MITRE ATT&CK techniques used in TL-2026-2129
Execution
T1059.010 AutoHotKey & AutoIT; T1204.001 Malicious Link; T1204.002 Malicious File
Command and Control
T1102.001 Dead Drop Resolver; T1219 Remote Access Tools
Persistence
Defense Evasion
T1497 Virtualization/Sandbox Evasion; T1684.001 Impersonation
Initial Access
T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1586.002 Email Accounts; T1608.005 Link Target
Reconnaissance
T1589.002 Email Addresses; T1598.004 Spearphishing Voice
Credential Access
Affected products and versions in Microsoft Teams Phishing
- Microsoft — Microsoft Teams
Vulnerable versions: Microsoft 365 tenants with default external collaboration/federation settings (external chat and calling allowed from any unmanaged tenant)
Fixed in: Tenants with external access, one-on-one chat, and calling restricted to an explicit allow-list of trusted domains; Teams hardened per Microsoft's October 2025 Secure Future Initiative guidance
Remediation for Microsoft Teams Phishing
Patches
- No vendor software patch applies; this abuses default Microsoft 365/Teams tenant configuration, not a vulnerability -- mitigation is configuration hardening of external-access and federation settings
Immediate actions
- Restrict Microsoft Teams external access/federation to an explicit allow-list of trusted partner tenant domains rather than the default "allow all external organizations" setting
- Restrict or disable external one-on-one chat and calling for unmanaged/unfamiliar tenants in the Teams admin center
- Block or tightly control installation of RMM tools (Quick Assist, AnyDesk, DWAgent) via application allow-listing / EDR execution policy
- Instruct helpdesk and general staff to never accept unsolicited IT-support contact over Teams chat, call, or meeting invite without independent, out-of-band verification
Workarounds
- Configure Teams to render the external-sender "(External)" indicator in a way that cannot be visually obscured by non-ASCII/emoji characters in the sender display name
- Enforce a persistent, non-dismissible external-caller warning banner for Teams voice calls and meetings, matching the warning already shown for chat
Longer-term hardening
- Continuously monitor Microsoft 365 unified audit log events (ChatCreated, MessageSent, UserAccepted, TeamsImpersonationDetected, TIMailData) for external-tenant contact patterns, especially from recently-registered ("baby") domains
- Adopt Microsoft's hardened Teams external-access defaults introduced under the Secure Future Initiative (per the October 2025 Microsoft Security Blog guidance)
- Deploy a threat-hunting query that surfaces one-on-one Teams chats with foreign-tenant users, excluding known partner domains, over a rolling window
- Require callback-based, out-of-band verification (not a number or contact supplied within the suspicious chat/call) before any employee grants screen-share or remote-control access
Weaknesses (CWE) in Microsoft Teams Phishing
CWE-451
Timeline of Microsoft Teams Phishing
- Microsoft Threat Intelligence begins observing Storm-1811 misusing Quick Assist in helpdesk-impersonation vishing attacks leading to Black Basta ransomware -- an early, separately-attributed precedent for the RMM-abuse tradecraft this campaign reuses.
- Hunters (Team AXON) responds to an incident at a U.S. critical-infrastructure organization later documented as the VEILDrive campaign (Sangria Tempest / Storm-1674), which abused Teams, SharePoint, Quick Assist, and OneDrive as C2 -- cited directly by this report as the technique-class precedent.
- Hunters publishes the VEILDrive research publicly, establishing Teams-based initial access and SaaS-hosted delivery as repeatable tradecraft rather than a one-off incident.
- Per Unit 42's retrospective account, Cloaked Ursa (APT29 / Midnight Blizzard) operationalizes Teams-based IT-helpdesk impersonation using compromised partner accounts to deliver credential-harvesting links and MFA-approval-request manipulation -- the earliest confirmed nation-state use of this exact pretext.
- Hunters (Team AXON, Alon Klayman & Tomer Kachlon) publish "Detecting Microsoft Teams Phishing: Hunting the Fake IT Helpdesk Threat," documenting this campaign's use of default Teams external-collaboration settings, an unbannered vishing vector, Burp Suite-manipulated SharePoint delivery, and Quick Assist/AnyDesk/DWAgent installs for persistence (source discloses month, not exact publish day).
- Microsoft publishes "Disrupting threats targeting Microsoft Teams," confirming multiple tracked actors (Storm-1811, Octo Tempest, Midnight Blizzard, Void Blizzard, Sangria Tempest, Storm-1674, Peach Sandstorm) abusing Teams for helpdesk vishing, RMM delivery, and device-code phishing, and announcing hardened external-access defaults under the Secure Future Initiative.
- UNC6692, a separately-attributed, previously-undocumented cluster, begins an IT-helpdesk-impersonation Teams campaign that later delivers the SNOW malware suite -- independent evidence the same TTP class continued escalating after the primary source's publication.
- The Hacker News reports UNC6692's SNOWBELT/SNOWBASIN/SNOWGLAZE malware suite delivered via Teams IT-helpdesk impersonation, an AutoHotkey loader staged on an attacker-controlled AWS S3 bucket, and a malicious Microsoft Edge extension used for credential harvesting.
- Palo Alto Networks Unit 42 publishes "When 'Hi, This Is IT' Comes Through Microsoft Teams," covering Cloaked Ursa/APT29 (late-2024) and UNC6692 (December 2025) Teams-based helpdesk-impersonation activity.
- Unit 42 researcher Brian Janower finds EtherRAT versions 1 through 9 in an open directory, with builds updated through this date, indicating active ongoing development of the RAT delivered through this Teams-helpdesk-impersonation technique class.
- The Register reports a further fake-IT-support Teams campaign, per Unit 42 researcher Brian Janower, delivering the EtherRAT Node.js RAT via HopToDesk/AnyDesk RMM installs -- confirming the technique class remained active as of mid-2026.
Sources cited for Microsoft Teams Phishing
- Detecting Microsoft Teams Phishing: Hunting the Fake IT Helpdesk Threat
- Leveraging Microsoft Teams for Initial Access
- Unmasking VEILDrive: Threat Actors Exploit Microsoft Services for C2
- VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware
- Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
- Storm-1811, Group G1046
- Disrupting threats targeting Microsoft Teams
- UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
- When "Hi, This Is IT" Comes Through Microsoft Teams
- Fake IT bods on Microsoft Teams coax workers into installing malware
Threats related to Microsoft Teams Phishing
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account Maintenance Update")
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry
- Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers
Detection coverage for TL-2026-2129
As of 2026-08-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2129 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.