A human-operated intrusion campaign abuses Microsoft Teams external collaboration to impersonate IT support and socially engineer users into granting remote access. Once control is established, attackers use PowerShell to download and silently install a malicious MSI package that stages a portable Node.js runtime and an obfuscated JavaScript implant. The implant provides persistent C2, enabling host and Active Directory reconnaissance, screen capture, and lateral movement via WinRM toward high-value assets like domain controllers.
hands-on-keyboard
1 post
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog