Hackers Using Teams to Deliver Malicious Content Posing as Microsoft Services
## Cybersecurity: Exploitation of Microsoft Teams
Cybersecurity: Exploitation of Microsoft Teams
A phishing campaign has been identified where threat actors exploit Microsoft Teams functionality to distribute malicious content that appears to originate from legitimate Microsoft services.
The attackers utilize the platform's "Invite a Guest" feature and use deceptive team names to bypass email security controls, delivering fraudulent billing notifications directly to users' inboxes.
This method exploits user trust in notifications from collaboration platforms. Instead of spoofing email addresses or injecting malicious URLs, attackers create new teams within Microsoft Teams using names that mimic urgent financial alerts, often referencing subscription renewals or auto-pay notices to induce panic.
Examples include team names such as: "Subscription Auto-Pay Notice (Invoice ID: 2025_614632PPOT_SAG Amount 629.98 USD). If you did not authorize or complete this monthly payment, please contact our support team urgently."
Once the team is created, attackers send invitations to external targets using the "Invite a Guest" feature. Recipients receive an email from a legitimate Microsoft address (e.g., noreply@email.teams.microsoft.com ).
Because the email infrastructure is genuine, it passes SPF, DKIM, and DMARC checks. However, the body of the email displays the malicious team name containing the fraudulent billing message and a support phone number in a large, prominent font.
This method exploits user trust in notifications from collaboration platforms.
This campaign is distinct in using phone-based social engineering (vishing). Instead of directing users to a credential-harvesting site, the text instructs victims to call a fraudulent support line to resolve the alleged charge.
To evade automated content filters, attackers use obfuscation techniques within the team name, employing character substitutions, mixed Unicode characters, and visually similar glyphs.
The scale of this operation is significant, with telemetry indicating a broad approach. Security researchers recorded 12,866 phishing messages distributed during the campaign's peak, averaging 990 messages daily, reaching approximately 6,135 distinct customers.
The distribution of targets suggests an attempt to exploit widespread Microsoft Teams adoption. The manufacturing, engineering, and construction sectors accounted for 27.4% of affected organizations, followed by the Technology/SaaS/IT sector at 18.6% and the Education sector at 14.9%. Other affected sectors included professional services, government, and finance.
The campaign had a global reach, focusing primarily on North American targets. Organizations in the United States comprised 67.9% of the victim pool. European entities accounted for 15.8%, followed by Asia at 6.4%.
In Latin America (LATAM), there was a concentration in Brazil and Mexico:
Brazil: 44% Mexico: 31% Argentina: 11% Colombia: 8% Chile: 4% Peru: 2%
This campaign highlights a critical gap in collaboration security: the reliance on content inspection within invitations generated by trusted platforms. Since the email delivery mechanism is legitimate, organizations cannot rely solely on email authentication protocols to block these threats.
Security teams are advised to educate users on scrutinizing unexpected Teams invitations, particularly those containing urgent financial language, phone numbers, or unusual character formatting.
Based on reporting by Cyber Security News.
