Microsoft Teams-Based Vishing Attack Tricks Victims Into Quick Assist Takeover
Threat actors are increasingly relying on social engineering rather than complex software vulnerabilities to breach corporate networks.
Threat actors are increasingly relying on social engineering rather than complex software vulnerabilities to breach corporate networks.
In November 2025, Microsoft’s Detection and Response Team (DART) investigated a notable identity-first intrusion where attackers successfully used Microsoft Teams voice phishing (vishing) to compromise a corporate device via Quick Assist.
This incident highlights the growing danger of weaponizing legitimate collaboration and remote support tools.
The intrusion began with a persistent vishing campaign. The threat actor actively impersonated internal IT support, initiating voice calls with multiple employees directly through Microsoft Teams.
While the first two targets recognized the suspicious behavior and refused to comply, a third employee fell for the deception.
Believing they were interacting with legitimate support staff, the user granted the attacker remote access to their machine using the built-in Windows Quick Assist application.
Malware Execution and Command-and-Control
Once remote interactive access was secured, the threat actor shifted from social engineering to hands-on keyboard exploitation.
Threat actors are increasingly relying on social engineering rather than complex software vulnerabilities to breach corporate networks.
They directed the compromised user to a malicious, attacker-controlled website containing a spoofed login form. After the victim entered their corporate credentials, the site initiated the download of several malicious payloads.
To establish a silent foothold, the attackers utilized a disguised Microsoft Installer (MSI) package. This package exploited trusted Windows processes to sideload a malicious dynamic link library (DLL).
This allowed the attackers to establish an outbound command-and-control connection while masquerading as legitimate software.
The threat actors rapidly expanded their access by deploying encrypted loaders and executing remote commands via standard administrative tools. They utilized proxy-based connections to obscure their network traffic.
By introducing specialized components for credential harvesting and session hijacking, the attackers gained sustained control.
They specifically relied on techniques designed to blend in with normal enterprise network activity to avoid triggering security alarms.
Microsoft DART quickly intervened to contain the breach. Investigators confirmed the vishing origins and prioritized actions to prevent any directory-level impact.
The team executed a targeted eviction, applying strict containment controls to protect privileged assets and stop lateral movement.
Forensic analysis verified that the attackers’ access was short-lived, their primary objectives were not met, and no persistence mechanisms remained on the network.
Based on reporting by GBHackers.
