Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware

Microsoft has reported an increase in the misuse of Microsoft Teams features by both cybercriminals and state-sponsored threat actors. These entities exploit the platform's capabilities—such as messaging, calls, and screen-sharing—along various stages of…

Microsoft has reported an increase in the misuse of Microsoft Teams features by both cybercriminals and state-sponsored threat actors. These entities exploit the platform's capabilities—such as messaging, calls, and screen-sharing—along various stages of their attack processes.

The widespread adoption of Microsoft Teams for collaboration has made it a significant target. Attackers leverage Teams throughout the attack lifecycle, using its trusted status to infiltrate networks, steal data, and deploy malware. The attack chain often begins with reconnaissance, utilizing tools like TeamsEnum and TeamFiltration to identify users and organizational vulnerabilities.

Subsequent stages include resource development, where attackers may compromise or impersonate legitimate entities to gain initial access. Techniques such as social engineering and tech support scams are commonly employed. Threat actors also use Teams chats to deliver malicious links and payloads, with tools like AADInternals and TeamsPhisher aiding in the distribution of malware.

Microsoft has reported an increase in the misuse of Microsoft Teams features by both cybercriminals and state-sponsored threat actors.
Zachary Burns · Thehackingpost

After establishing access, attackers aim to maintain persistence and escalate privileges. This can involve adding guest accounts, abusing authentication flows, or using phishing to ensure long-term access. With elevated permissions, attackers conduct discovery and lateral movement using tools like AzureHound to map configurations and identify valuable data.

In some cases, external communication settings are altered to facilitate lateral movement between organizations. The attack culminates in data collection, command and control, and exfiltration stages, often leading to financial theft through extortion or ransomware.

Advertisement

Security experts recommend implementing a defense-in-depth strategy, focusing on strengthening identity and access controls, monitoring for unusual activities within Teams, and enhancing user security awareness through continuous training.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories