Microsoft has warned businesses about a new cyberattack campaign in which hackers impersonate internal IT support staff on Microsoft Teams. These attackers trick employees into granting them remote access to their work computers by falsely claiming they are performing necessary security updates, adjusting spam filters, or verifying accounts. Once access is granted, attackers use tools like Quick Assist or other legitimate remote maintenance software to interactively control the employee’s workstation, potentially moving deeper into the company's network and reaching critical servers that manage user authentication.
According to Microsoft’s security blog, once inside the system, attackers use PowerShell commands to download and install an MSI package hosted on cloud storage. This package includes the official and portable version of Node.js, a popular software development tool. The software is installed in a user’s profile folder and launched through a shortcut named "EdgeUpdate," which is added to the Windows startup folder or registry. This setup allows attackers to maintain communication with a remote server using HTTPS, receiving JavaScript instructions to perform further actions. Microsoft researchers observed that attackers also map the Windows domain using ADSI and WMI protocols, query Active Directory, and load DLL files using the rundll32 command. They then move through the network to domain controllers and certification authorities using the WinRM remote administration protocol.
Microsoft highlights that this type of attack is different from standard phishing scams because it involves a human operator at each stage, making it more complex and harder to detect. The company recommends that organizations verify the identity of any technical support contact through internal, validated channels and implement multi-factor authentication using Microsoft Entra Conditional Access. Other recommendations include restricting the WinRM protocol to authorized administrative workstations and keeping a list of approved remote maintenance tools up to date. Microsoft has also introduced brand impersonation protection in Teams, which alerts users during suspicious calls, and is rolling it out to early adopters starting in February.
In France, the government’s cyberfraud monitoring platform, Cybermalveillance.gouv.fr, reported over 13,000 cases related to this type of impersonation scam in 2024, ranking it as the third most common cyberthreat. A study by Microsoft and Ifop cited by the platform found that only 16 percent of people over 60 know the correct steps to take if they encounter online fraud, while nearly 40 percent would first consult a family member or friend if they faced a computer-related problem.
Microsoft Warns of Teams Impersonation Campaign Involving Remote Access and Network Infiltration
AI-rewritten from original reportingHow it works
microsoftteamscyberattacknode-jsremote-accessphishing



