Microsoft Alerts Users as Hackers Exploit Teams Features to Spread Malware
Microsoft has advised organizations to enhance security measures for Microsoft Teams as threat actors exploit its collaboration features such as chat, meetings, voice/video, screen sharing, and app integrations. These features are being used to gain…
Microsoft has advised organizations to enhance security measures for Microsoft Teams as threat actors exploit its collaboration features such as chat, meetings, voice/video, screen sharing, and app integrations. These features are being used to gain initial access, persist, move laterally, and exfiltrate data.
Microsoft's Secure Future Initiative has improved default security settings. However, effective defense requires active configuration of identity, endpoint, data/application, and network controls, based on observed real-world attack techniques.
Reconnaissance: Threat actors use Microsoft Graph and open-source tools to enumerate users, teams, channels, tenant configurations, and cross-tenant policies. Data Exposure: Visibility settings, external access, multi-tenant collaboration, and guest/anonymous settings can unintentionally reveal valuable signals. Social Engineering: Adversaries map relationships and permissions to craft targeted phishing lures and social engineering attacks. Resource Development: Actors leverage legitimate Entra ID tenants, custom domains, and branded assets to impersonate internal IT departments. Credential Theft: Spoofing IT workflows and using Teams-like branding to distribute credential theft tools and remote access software.
Social Engineering: Utilizing Teams chat and meetings for distributing Remote Monitoring and Management (RMM) tools and directing users to malicious sites. Malvertising: Delivering fake Teams installers that deploy information stealers. Session Hijacking: Exploiting adaptive authentication, MFA fatigue, and token theft to maintain access.
These features are being used to gain initial access, persist, move laterally, and exfiltrate data.
Persistence: Established through startup shortcuts, accessibility features, or adding guest users and credentials to Teams accounts. Lateral Movement: Compromising admin roles or abusing external communication and tenant trust settings for expanded control.
Data Collection: Targeting Teams chats, channels, and linked data in OneDrive/SharePoint. Command and Control: Hiding communications in Teams messages, adaptive cards, or webhook flows.
Implement network-layer controls, conditional access, and continuous audit of admin roles to prevent privilege escalation. Monitor Teams-specific signals such as suspicious meeting invites, rapid chat outreach, unexpected bot/app activity, and anomalous presence access to detect and disrupt campaigns.
Based on reporting by GBHackers.
