Cybercriminals Exploit Microsoft Teams Chats to Deliver Malware

Attackers Exploit Microsoft Teams to Deploy Malware and Maintain Access

Cybercriminals have devised a sophisticated, multi-layered attack that weaponizes Microsoft Teams to infiltrate corporate networks, deliver malicious payloads, and establish persistent remote access.

By taking advantage of Teams’ trusted status as an internal business communication tool, attackers circumvent traditional email-based security defenses, making this an emerging and dangerous threat.

How the Attack Unfolds

Security experts at Ontinue’s Cyber Defence Centre recently uncovered an incident where attackers combined social engineering, voice phishing (vishing), and legitimate remote access software to compromise enterprise systems.

The attack began with a deceptive Teams message containing a PowerShell command. Disguised as IT support personnel, the hackers tricked users into executing the malicious script, while also using Quick Assist, a built-in Windows tool, to gain direct remote access.

Once inside, the attackers deployed a malware-laden PowerShell command that triggered a stealthy infection process. This included DLL sideloading, where a legitimate, signed TeamViewer.exe binary was used to execute a rogue TV.dll file, evading security detection.

Hidden Backdoor and Persistent Access

Further analysis revealed a second-stage payload—a JavaScript-based backdoor running through Node.js, disguised as hcmd.exe. This allowed attackers to establish a continuous connection to their command-and-control (C2) servers, enabling remote execution of commands and data exfiltration.

Cybersecurity analysts have linked this attack pattern to a known group, Storm-1811, which frequently employs vishing and social engineering tactics. Microsoft and Trend Micro have documented similar campaigns distributing malware like DarkGate via Teams calls, tricking users into installing remote access tools such as AnyDesk.

Defensive Measures and Mitigation Strategies

The attack chain aligns with several MITRE ATT&CK techniques, including:

  • T1105 – Ingress Tool Transfer
  • T1656 – Impersonation
  • T1219 – Remote Access Software
  • T1218 – Signed Binary Proxy Execution
  • T1197 – BITS Jobs

To mitigate these threats, organizations should:

Disable or remove Quick Assist and other unnecessary remote access tools.
Restrict external Teams communications to prevent unauthorized messages.
Implement endpoint monitoring to detect suspicious PowerShell activity.
Educate employees on social engineering tactics used in these attacks.

In response to the growing abuse of Quick Assist, Microsoft has announced new security alerts to warn users about potential tech support scams.

As attackers continue to exploit collaboration tools like Microsoft Teams, businesses must enhance their security frameworks and train users to recognize evolving cyber threats.

More Articles & Posts