MICROSOFT Threat Intelligence has identified a human-operated intrusion campaign exploiting Microsoft Teams to impersonate IT support. Attackers socially engineer users to enable remote access via legitimate tools, followed by installing malicious scripts that facilitate extensive reconnaissance and lateral movement within corporate networks. The attack leverages familiar enterprise software, blending in with normal operations, and targets critical infrastructure such as domain controllers.
The blog outlines the attack chain from initial contact to data theft, providing mitigation strategies to counter these threats, including user education, verification of external communications, stricter security protocols for remote access, and monitoring of remote support tools.