Microsoft is warning about a sophisticated hacking campaign that begins with a deceptive message on Microsoft Teams and can lead to ransomware attacks and data theft. In a recent report published on its official blog, the company described how unknown cybercriminals are contacting employees at various businesses through Teams chats, impersonating IT support staff. These attackers are tricking victims into granting them remote access to their computers through screen sharing or remote management tools. Once access is granted, the attackers install malware loaders and other malicious software to prepare for further exploitation.
The attack doesn’t stop at the initial infection. After gaining access, the threat actors perform reconnaissance to map out the internal network, discover security tools, and identify virtualization environments. They also periodically capture screenshots of the user’s desktop to gather more information. This stage is focused on espionage and gathering intelligence about the company’s infrastructure. The attackers then use native tools and Active Directory Service Interfaces (ADSI) queries to discover domain accounts, servers, and user details, allowing them to move laterally within the network and expand their access.
Once the attackers have mapped the network and gathered enough information, they begin extracting valuable data. In some cases, this is followed by a ransomware attack that encrypts files, forcing the company to pay a ransom for decryption. Microsoft has not named the specific groups behind these attacks, referring to them only as "threat actors." However, it is known that several cybercriminal groups are using the "fake IT support via Teams" method. These include groups like Cozy Bear, FIN7, and Storm-1811, which are linked to Russia, as well as ShinyHunters, a group known for data theft rather than encryption-based ransomware.
To protect against such attacks, Microsoft recommends improving user education and implementing internal authentication phrases for helpdesk interactions. Employees should be trained to recognize suspicious communication from external sources. Companies are also urged to verify any unsolicited support requests and strengthen security measures for Microsoft Teams and email systems. Microsoft suggests using Microsoft Defender for Office 365 with features like Safe Links and Zero-hour auto purge (ZAP), which help neutralize malicious links and remove harmful messages immediately after delivery.
Microsoft Warns of Ongoing Ransomware Campaign via Teams Impersonation
AI-rewritten from original reportingHow it works
microsoftransomwareteamssocialengineeringcybersecuritydataexfiltration



