Fake IT technicians on Microsoft Teams: how hackers gain corporate access
Microsoft Threat Intelligence reports an intrusion campaign that exploits Teams' external collaboration to impersonate technical support.

Microsoft Threat Intelligence has detected a human-operated intrusion campaign that exploits the external collaboration features of Microsoft Teams. The malicious actors use social engineering techniques to impersonate IT technical support, thereby succeeding in gaining remote access to corporate systems.
Once the remote session is established, the attackers install a Node.js-based implant. Subsequently, by exploiting legitimate tools, the threat actors initiate lateral movements within the network to extend access across the corporate level.
Microsoft Defender security solutions help detect and disrupt this specific malicious activity, protecting the affected infrastructures.
