North America
Microsoft Teams users
Microsoft's Detection and Response Team revealed a Microsoft Teams voice phishing (vishing) campaign that targets Microsoft users.
In this campaign, threat actors impersonate IT support and trick users into granting remote access via Microsoft's Quick Assist, enabling initial device compromise. Once access is established, attackers shift from social engineering to hands-on keyboard compromise. They then direct users to malicious websites that prompt them to enter corporate credentials into spoofed forms, triggering the download of multiple malicious payloads.
This incident highlights a growing class of attacks that exploit user trust, collaboration platforms and legitimate built-in tools to gain access and move laterally within environments.
How it could affect your business
Attackers are increasingly exploiting trusted tools and collaboration platforms to gain unauthorized access. In these incidents, threat actors create a sense of urgency and trust that can override user caution. Organizations should restrict inbound communication from unmanaged Teams accounts, adopt an allowlist approach for trusted external domains and review the use of remote access tools to reduce the risk of such incidents. Raising user awareness is also critical so employees can recognize suspicious requests before they cause damage.