{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/collaboration-abuse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Teams","Windows","Active Directory"],"_cs_severities":["high"],"_cs_tags":["social-engineering","collaboration-abuse","remote-access","lateral-movement"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft Threat Intelligence has documented a high-impact, human-operated intrusion campaign that leverages Microsoft Teams external collaboration features to facilitate social engineering. Threat actors impersonate IT or helpdesk personnel to deceive users into granting interactive remote access via legitimate support tools. Once access is established, the attackers execute PowerShell commands to download and silently install a malicious MSI package. This package stages a portable Node.js runtime and an obfuscated JavaScript implant within user-writable directories (e.g., LocalAppData).\u003c/p\u003e\n\u003cp\u003eThe implant enables persistent command execution and C2 via HTTPS polling. Unlike automated malware, this campaign follows a hands-on-keyboard playbook, conducting extensive host and Active Directory reconnaissance, capturing screenshots, and utilizing native administrative tools for lateral movement. The attackers frequently leverage Windows Remote Management (WinRM) to pivot toward high-value assets, including domain controllers. This intrusion is particularly dangerous because it uses legitimate collaboration, installation, and administration tools to blend into normal enterprise operations, allowing actors to maintain long-term access for data theft or ransomware deployment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access via Teams (T1566.003): Threat actor initiates contact impersonating IT/helpdesk and persuades the user to approve a remote screen-share or connection request.\u003c/li\u003e\n\u003cli\u003eRemote session and payload delivery: Attacker uses the remote session to execute PowerShell commands that download a malicious MSI from cloud storage.\u003c/li\u003e\n\u003cli\u003eSilent execution: The attacker uses msiexec to silently install the malicious MSI package.\u003c/li\u003e\n\u003cli\u003eImplant staging: The installer drops a script-based loader and fetches a legitimate portable Node.js runtime if not present on the system.\u003c/li\u003e\n\u003cli\u003eCommand-and-control establishment: The loader decrypts and executes the JavaScript implant, which initiates HTTPS polling to a C2 server for tasking.\u003c/li\u003e\n\u003cli\u003eReconnaissance and collection: The attacker uses native tools and ADSI queries to enumerate domain accounts and servers while periodically capturing user desktop screenshots.\u003c/li\u003e\n\u003cli\u003eLateral movement: The attacker utilizes WinRM (TCP port 5985) to pivot from the compromised workstation to domain controllers and other high-value infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis campaign results in full interactive access to internal systems, enabling attackers to perform lateral movement, credential harvesting, and domain enumeration. The observed reconnaissance patterns toward identity infrastructure (domain controllers, certificate authorities) are consistent with preparatory stages for ransomware deployment, data exfiltration, or long-term persistence in enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize detection and response by monitoring for unusual administrative activity and collaboration platform abuse.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable monitoring for msiexec processes spawned by non-standard parent processes or PowerShell.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of portable Node.js runtimes or unexpected JavaScript execution within user-writable directories (e.g., LocalAppData).\u003c/li\u003e\n\u003cli\u003eImplement strictly scoped monitoring for lateral movement using WinRM (TCP 5985) originating from non-administrative endpoints.\u003c/li\u003e\n\u003cli\u003eTrain users to recognize and report unsolicited external Teams communications or instructions to override security warnings.\u003c/li\u003e\n\u003cli\u003eDeploy endpoint detection and response (EDR) rules to identify unauthorized ADSI queries and suspicious process spawning from remote management software.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:00:27Z","date_published":"2026-09-03T00:00:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-teams-impersonation/","summary":"Threat actors impersonate IT helpdesk staff in Microsoft Teams to socially engineer users into granting remote access, subsequently deploying a Node.js-based implant for reconnaissance and lateral movement.","title":"Threat Actors Impersonate IT Support via Microsoft Teams to Deploy Node.js Implants","url":"https://feed.craftedsignal.io/briefs/2026-09-teams-impersonation/"}],"language":"en","title":"CraftedSignal Threat Feed - Collaboration-Abuse","version":"https://jsonfeed.org/version/1.1"}