Microsoft: Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access

Microsoft: Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access

Microsoft Teams Abused in Rising IT Support Impersonation Attacks as Phishing Shifts from Email

Cybercriminals are increasingly exploiting Microsoft Teams to impersonate internal IT support, tricking employees into granting remote access or divulging corporate credentials. This shift comes as traditional email phishing particularly campaigns tied to the Tycoon2FA phishing-as-a-service (PhaaS) platform declines sharply following a March 2026 disruption that crippled its infrastructure.

Microsoft’s Q2 2026 email threat data reveals a 92% drop in Tycoon2FA-linked phishing since late 2025, alongside a 41% decline in QR-code and CAPTCHA-gated attacks in May and June. However, the reduction in email-based threats has not translated to fewer social engineering attacks instead, attackers are migrating to collaboration platforms like Teams, where messages often bypass secure email gateways and exploit implicit trust in internal communications.

Teams-Based Phishing and Vishing Surge

Microsoft Threat Intelligence reports a tenfold increase in malicious Teams call attempts since mid-2025, with attackers timing calls during weekday business hours to blend in with legitimate IT activity. The most concerning tactic involves cross-tenant Teams chats, where adversaries pose as IT support or helpdesk staff, warning of imminent account lockouts or security incidents. Victims are urged to "verify" access or initiate a remote assistance session using tools like Quick Assist, allowing attackers to escalate privileges to domain admin within minutes and exfiltrate data under the guise of routine maintenance.

Attackers are refining their approach by adopting generic or SaaS-style display names (e.g., "ClickFix Support") to evade keyword-based detections and heighten urgency over authenticity. Microsoft observed that voice phishing (vishing) attempts via Teams have surged, with weekly malicious call volumes nearing 10 times mid-2025 levels by the end of Q2 2026.

While Teams abuse rises, email-based phishing remains massive but increasingly optimized. Microsoft detected 7.6 billion email phishing threats in Q2 2026, primarily focused on credential harvesting rather than malware delivery. Notable campaigns include multi-stage AiTM (Adversary-in-the-Middle) attacks combining:

  • Nested EML files
  • Calendar invitations
  • Microsoft authentication redirects
  • OAuth token theft

PDF attachments accounted for 24–31% of attacks, though their volume declined 41% in May and 4% in June. Meanwhile, the decline of Tycoon2FA forced off Cloudflare and onto .RU domains has left a gap in the phishing-as-a-service market, with no single replacement yet emerging.

Large-Scale Campaign Targets U.S. Organizations

Microsoft Defender Research identified a phishing campaign targeting 107,000 users across nearly 19,000 organizations, almost exclusively in the United States. The shift to Teams reflects attackers’ adaptation to saturated email defenses, leveraging a less monitored, high-trust channel for one-to-one lures and interactive voice calls.

Indicators of Compromise (IOCs)

Recent campaigns have used domains like:

  • 9i6pokerdepot[.]com (DKIM-signed sending domain)
  • t90141296286.p.clickup-attachments[.]com (hosting stage 2 BAT dropper)
  • pixeldrain[.]com/api/file/3v92oJiL (final payload delivery)

Attackers also employed nested EML attachments (e.g., "Re: Teams Archive Recording for {{DATE2}}.eml") and batch files (e.g., Financial_report.bat) to deploy malware.

Defensive Recommendations (Fact-Based)

To counter Teams-based impersonation, security teams are advised to:

  • Tighten external access policies for collaboration platforms.
  • Restrict or harden remote-support tools like Quick Assist.
  • Enforce phishing-resistant MFA (e.g., FIDO2/WebAuthn security keys) for privileged roles.
  • Leverage Conditional Access policies for admin accounts.
  • Educate users on legitimate IT contact methods to verify support requests.

Microsoft’s Defender SmartScreen, Safe Links/Safe Attachments, and automatic attack disruption features are positioned as controls to limit the impact of successful social engineering attempts.

Source: https://gbhackers.com/microsoft-teams-abused-2/

Microsoft Security cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security

"id": "MIC1784881900",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '107,000 users',
                        'industry': 'Various (nearly 19,000 organizations)',
                        'location': 'United States',
                        'name': 'Multiple U.S. organizations',
                        'type': 'Various'}],
 'attack_vector': ['Microsoft Teams',
                   'Cross-tenant Teams chats',
                   'Remote assistance tools (Quick Assist)',
                   'Voice phishing (vishing)',
                   'Nested EML files',
                   'PDF attachments',
                   'OAuth token theft'],
 'data_breach': {'data_exfiltration': 'Yes (under guise of routine '
                                      'maintenance)',
                 'file_types_exposed': ['EML', 'PDF', 'BAT'],
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (credentials, PII, OAuth tokens)',
                 'type_of_data_compromised': ['Corporate credentials',
                                              'OAuth tokens',
                                              'Personally identifiable '
                                              'information (PII)']},
 'date_detected': '2026-06-30',
 'date_publicly_disclosed': '2026-06-30',
 'description': 'Cybercriminals are increasingly exploiting Microsoft Teams to '
                'impersonate internal IT support, tricking employees into '
                'granting remote access or divulging corporate credentials. '
                'This shift follows a decline in traditional email phishing, '
                'particularly campaigns tied to the Tycoon2FA '
                'phishing-as-a-service (PhaaS) platform, after its '
                'infrastructure was disrupted in March 2026. Attackers are '
                'migrating to collaboration platforms like Teams, where '
                'messages often bypass secure email gateways and exploit '
                'implicit trust in internal communications.',
 'impact': {'brand_reputation_impact': 'Potential erosion of trust in internal '
                                       'communications',
            'data_compromised': ['Corporate credentials',
                                 'OAuth tokens',
                                 'Personally identifiable information (PII)'],
            'identity_theft_risk': 'High (due to credential theft and PII '
                                   'exposure)',
            'operational_impact': ['Privilege escalation to domain admin',
                                   'Data exfiltration under guise of routine '
                                   'maintenance'],
            'systems_affected': ['Microsoft Teams',
                                 'Email systems',
                                 'Remote assistance tools']},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Attackers are adapting to saturated email defenses by '
                    'exploiting less monitored, high-trust channels like '
                    'Microsoft Teams for social engineering. Traditional '
                    'phishing-as-a-service platforms like Tycoon2FA are '
                    'declining, but new tactics (e.g., vishing, cross-tenant '
                    'Teams chats) are emerging. Organizations must harden '
                    'collaboration platforms and remote-support tools to '
                    'mitigate these threats.',
 'motivation': ['Credential theft',
                'Privilege escalation',
                'Data exfiltration',
                'Financial gain'],
 'post_incident_analysis': {'corrective_actions': ['Implement '
                                                   'phishing-resistant MFA for '
                                                   'all privileged accounts.',
                                                   'Restrict or monitor '
                                                   'remote-support tools.',
                                                   'Enforce stricter external '
                                                   'access policies for '
                                                   'collaboration platforms.',
                                                   'Enhance user education on '
                                                   'social engineering '
                                                   'tactics.'],
                            'root_causes': ['Implicit trust in internal '
                                            'communications (e.g., Microsoft '
                                            'Teams)',
                                            'Lack of phishing-resistant MFA '
                                            'for privileged roles',
                                            'Unrestricted use of '
                                            'remote-support tools like Quick '
                                            'Assist',
                                            'Weak external access policies for '
                                            'collaboration platforms']},
 'recommendations': ['Tighten external access policies for collaboration '
                     'platforms like Microsoft Teams.',
                     'Restrict or harden remote-support tools such as Quick '
                     'Assist.',
                     'Enforce phishing-resistant MFA (e.g., FIDO2/WebAuthn '
                     'security keys) for privileged roles.',
                     'Leverage Conditional Access policies for admin accounts.',
                     'Educate users on legitimate IT contact methods to verify '
                     'support requests.',
                     'Deploy Microsoft Defender SmartScreen, Safe Links/Safe '
                     'Attachments, and automatic attack disruption features.'],
 'references': [{'date_accessed': '2026-06-30',
                 'source': 'Microsoft Threat Intelligence'},
                {'date_accessed': '2026-06-30',
                 'source': 'Microsoft Defender Research'}],
 'response': {'enhanced_monitoring': ['Microsoft Defender SmartScreen',
                                      'Safe Links/Safe Attachments',
                                      'Automatic attack disruption'],
              'remediation_measures': ['Tightening external access policies '
                                       'for collaboration platforms',
                                       'Restricting or hardening '
                                       'remote-support tools like Quick Assist',
                                       'Enforcing phishing-resistant MFA '
                                       '(e.g., FIDO2/WebAuthn security keys) '
                                       'for privileged roles',
                                       'Leveraging Conditional Access policies '
                                       'for admin accounts',
                                       'Educating users on legitimate IT '
                                       'contact methods']},
 'title': 'Microsoft Teams Abused in Rising IT Support Impersonation Attacks '
          'as Phishing Shifts from Email',
 'type': ['Phishing', 'Vishing', 'Social Engineering', 'Credential Harvesting'],
 'vulnerability_exploited': ['Implicit trust in internal communications',
                             'Lack of phishing-resistant MFA',
                             'Unrestricted remote-support tools',
                             'Weak external access policies for collaboration '
                             'platforms']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.