Microsoft Threat Intelligence has identified a human-operated intrusion campaign that exploits Microsoft Teams to impersonate IT support personnel, manipulating users into granting remote access. This attack involves the use of PowerShell to download and install a malicious MSI package, which subsequently stages a Node.js runtime and a JavaScript implant for persistent command execution and command-and-control (C2) capabilities. The campaign is characterized by extensive reconnaissance and lateral movement within enterprise networks, posing significant risks to organizational security.
Risk to Enterprise Environments
The threat actors leverage Microsoft Teams’ external collaboration features to initiate contact, appearing as legitimate IT support. This method circumvents traditional email phishing defenses, relying on social engineering to convince users to bypass security warnings and grant remote access. Once access is obtained, the attackers can:
- Establish interactive, credential-backed system access through legitimate remote support tools.
- Execute malicious code using trusted installers and runtimes.
- Map the host and Active Directory environment through automated discovery.
- Move laterally toward high-value infrastructure using Windows Remote Management (WinRM).
- Capture on-screen activity for further exploitation.
Attack Chain Overview
The attack unfolds in multiple stages, beginning with social engineering through Teams, followed by payload delivery, execution, reconnaissance, and lateral movement:
- Initial Access via Teams: The threat actor initiates a Teams chat or call, impersonating IT staff, and persuades the user to grant remote access.
- Remote Session and MSI Delivery: During the session, the actor uses PowerShell to download and silently install a malicious MSI.
- Node.js Runtime and Implant Staging: The MSI installs a script-based loader and an encrypted implant file.
- Script-based Bootstrap and Execution: The MSI executes hidden bootstrap code to run the JavaScript implant.
- Command-and-Control and Tasking: The implant communicates with its C2 server to receive tasks.
- Domain Discovery: The operator enumerates domain accounts and servers.
- Follow-on Payload Execution: Additional payloads are executed through rundll32.
- Lateral Movement via WinRM: The operator initiates connections to domain-joined systems.
For further details on this campaign, refer to the analysis provided by Microsoft Threat Intelligence.
Mitigation and Response Recommendations
Organizations should treat unsolicited external support contacts as suspicious and implement layered defenses across identity, endpoint, and collaboration layers. Key recommendations include:
- Reinforce user education: Train employees to recognize external-tenant indicators and avoid granting remote access to unsolicited contacts.
- Verify unsolicited support contacts: Confirm any external Teams interactions through known internal channels before granting access.
- Harden Microsoft Teams: Apply security best practices and restrict external access to trusted domains.
- Enforce phishing-resistant access controls: Implement multi-factor authentication and manage device compliance.
- Control remote support tools: Monitor and limit the use of remote management software.
By following these recommendations, organizations can better protect themselves against this evolving threat landscape.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



