Impersonating IT Support: How Threat Actors Turn a Remote Session into Enterprise-Wide Access
Microsoft, Wednesday, September 2nd, 2026
Microsoft Threat Intelligence tracks attackers abusing Teams external chat to pose as helpdesk staff and seize remote sessions.
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session.
Once remote control is established through RMM tooling, the actor uses PowerShell to download and silently install a malicious MSI package.
That package stages a portable Node.js runtime and an obfuscated JavaScript implant providing persistent command execution and command-and-control. Unlike commodity phishing that ends with an infostealer, the campaign follows a full hands-on-keyboard playbook toward enterprise-wide access.