Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 342, Issue 1IT Vendor NewsMicrosoft

Impersonating IT Support: How Threat Actors Turn a Remote Session into Enterprise-Wide Access

Microsoft, Wednesday, September 2nd, 2026

Microsoft Threat Intelligence tracks attackers abusing Teams external chat to pose as helpdesk staff and seize remote sessions.

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session.

Once remote control is established through RMM tooling, the actor uses PowerShell to download and silently install a malicious MSI package.

That package stages a portable Node.js runtime and an obfuscated JavaScript implant providing persistent command execution and command-and-control. Unlike commodity phishing that ends with an infostealer, the campaign follows a full hands-on-keyboard playbook toward enterprise-wide access.

more →  ·  More from Microsoft →