Microsoft: Teams increasingly abused in helpdesk impersonation attacks
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户已经给出了文章的详细内容,我得先仔细阅读并理解其中的关键信息。 文章主要讲的是微软警告黑客滥用Teams协作功能,伪装成IT人员诱骗员工提供远程访问权限。黑客利用合法工具如Quick Assist和Rclone进行横向移动和数据窃取。攻击过程分为多个阶段,包括初始接触、侦察、植入恶意软件、横向移动和数据外泄。微软建议限制远程工具的使用,并监控异常活动。 接下来,我需要提取这些关键点:威胁行为者、滥用Teams、伪装IT人员、诱骗提供访问权限、利用合法工具、多阶段攻击链、数据窃取建议措施等。 然后,我要把这些信息浓缩到100字以内,确保涵盖主要威胁、攻击方法和微软的建议。要注意用词简洁明了,避免重复。 最后,检查一下是否符合用户的要求:直接写描述,不使用特定开头语,并且控制在100字以内。 </think> 微软警告称,黑客正滥用Microsoft Teams协作功能,伪装成IT或客服人员诱骗员工提供远程访问权限。通过合法工具如Quick Assist和Rclone进行横向移动和数据窃取。攻击链分九个阶段,从初始接触到数据外泄。微软建议限制远程工具使用并监控异常活动。 2026-4-20 15:16:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:15 收藏

Microsoft: Teams increasingly abused in helpdesk impersonation attacks

Microsoft is warning of threat actors increasingly abusing external Microsoft Teams collaboration and relying on legitimate tools for access and lateral movement on enterprise networks.

The hackers impersonate IT or helpdesk staff to contact employees through cross-tenant chats and trick them into providing remote access for data theft purposes.

Microsoft has observed multiple intrusions with a similar attack chain that used commercial remote management software, such as Quick Assist, and the Rclone utility to transfer files to an external cloud storage service.

Wiz

The tech giant notes that follow-on malicious activity is hard to discern from normal operations because of the heavy use of legitimate applications and native administrative protocolos.

“Threat actors are increasingly abusing external Microsoft Teams collaboration to impersonate IT or helpdesk personnel and convince users to grant remote assistance access,” Microsoft says.

“From this initial foothold, attackers can leverage trusted tools and native administrative protocols to move laterally across the enterprise and stage sensitive data for exfiltration—often blending into routine IT support activity throughout the intrusion lifecycle,” the company added.

Multi-stage attack

In a recent report, Microsoft describes a nine-stage attack chain that begins with the threat actor contacting the target via an external Teams chat, posing as a member of the company's IT staff  and claiming they need to address an account issue or perform a security update.

The goal is to convince the target to start a remote support session, usually via Quick Assist, which gives the attacker direct control of the employee's machine.

Malicious message sent to targets
Malicious message sent to targets
Source: Microsoft

From there, the attacker performs quick reconnaissance using Command Prompt and PowerShell, checking privileges, domain membership, and network reachability to evaluate the potential for lateral movement.

Then they drop a small payload bundle in user-writable locations such as ProgramData and execute the malicious code through a trusted, signed application (e.g., Autodesk, Adobe Acrobat/Reader, Windows Error Reporting, data loss prevention software) via DLL side-loading.

The HTTPS-based communication to the command-and-control (C2) established this way blends into normal outbound traffic, making it more difficult to detect.

With the infection established and persistence secured via Windows Registry modifications, the attacker proceeds to abuse Windows Remote Management (WinRM) to move laterally across the network, targeting domain-joined systems and high-value assets such as domain controllers.

They then deploy additional remote management software tools onto reachable systems and use Rclone or similar tools to collect and exfiltrate sensitive data to external cloud storage points.

Attack stages
Attack stages
Source: Microsoft

Microsoft notes that this exfiltration step is rather targeted, employing filters to focus only on valuable information, reduce transfer volume, and improve operational stealth.

Microsoft reminds users to treat external Teams contacts as untrusted by default, and recommends that administrators restrict or closely monitor remote assistance tools, and limit WinRM usage to controlled systems.

Apart from this, the company draws attention to the Teams security warnings that explicitly flag communications from persons outside the organization and potential phishing attempts.

tines

99% of What Mythos Found Is Still Unpatched.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what's exploitable, proves controls hold, and closes the remediation loop.


文章来源: https://www.bleepingcomputer.com/news/security/microsoft-teams-increasingly-abused-in-helpdesk-impersonation-attacks/
如有侵权请联系:admin#unsafe.sh