HomeCyber BalkansHackers Pose as IT Support on Microsoft Teams to Gain Control of...

Hackers Pose as IT Support on Microsoft Teams to Gain Control of Employee PCs

Published on

spot_img

In a concerning development within the cybersecurity landscape, a recently identified campaign has demonstrated a sophisticated method of human-operated intrusion targeting organizations. Attackers are leveraging Microsoft Teams’ external collaboration features to impersonate internal IT or helpdesk staff, manipulating employees into granting remote control of their personal computers. This alarming tactic enables the perpetrators to infiltrate broader critical enterprise infrastructure.

The intricacy of this campaign lies in its operational mechanics. Notably, it does not exploit any vulnerabilities within Microsoft Teams itself. Instead, it exploits the inherent trust organizations place in familiar support workflows. The attackers ingeniously combine chats or calls via Teams, remote assistance tools, PowerShell scripts, malicious Microsoft Installer (MSI) files, and portable Node.js binaries. The reliance on conventional Windows administration protocols further underpins the campaign’s effectiveness, allowing intruders to orchestrate an invasive invasion that can escalate from an individual employee’s device to essential network components, including domain controllers and certificate authorities.

The initial contact is initiated by these attackers from an external Microsoft 365 tenant, masquerading as IT support personnel. They employ a host of urgent tactics designed to provoke a hasty response, such as alerts about security updates, changes to spam filters, or time-sensitive account verification requests. This manipulation is designed to heighten a sense of urgency, compelling users to comply with seemingly benign screen-sharing requests or to provide Quick Assist access codes.

According to Microsoft, this method corresponds to the MITRE ATT&CK framework technique T1566.003, categorized as “Spearphishing via Service.” The campaign’s distinctive nature emerges from the fact that the interaction occurs within an enterprise collaboration application rather than through the traditional avenues of phishing, such as emails. In some scenarios, attackers escalate their manipulation techniques by supplementing Teams communications with voice phishing, commonly referred to as vishing. Such calls afford operators the opportunity to coach victims through the installation of malicious software or the provision of remote access, without leaving a trace of harmful commands in chat logs.

Once a victim inadvertently grants the attackers control through a legitimate remote monitoring and management tool or Quick Assist, malicious activities can commence. The operator utilizes PowerShell to download and execute a malicious Windows Installer package from a cloud storage platform. This installation is performed silently, leveraging the msiexec command with the /qn flag, effectively masking any installation prompts from the victim.

The MSI installer often carries innocuous names mimicking legitimate updates, such as “devfix” or “Hotfix.” Within this installer are various components staged in the user’s LocalAppData directory, including a script-based loader and an encrypted JavaScript implant. Should the host lack Node.js, the malware retrieves a legitimate, portable version of Node.js from its official distribution site. This approach allows attackers to utilize a signed and trusted environment for executing potentially dangerous JavaScript, complicating detection efforts.

An additional layer of sophistication is evident in the persistence mechanisms employed by the attackers. The MSI packages create entries in the registry’s Run key or the Startup folder, ensuring that the backdoor is initiated every time the user logs in. Microsoft’s Threat Intelligence has observed that, while Teams provides various external tenant labels, acceptance prompts, and phishing indicators, the success of this campaign hinges on victims overriding these critical warnings.

The implanted malware communicates with its command-and-control (C2) infrastructure utilizing randomized HTTPS long polling. The data exchanged is treated as JavaScript and dynamically executed, offering attackers a broad range of access to process executions, file system activities, environment variables, and Node.js modules. The malware not only collects detailed information about the host system, which includes hardware specifications, disk details, and software environments, but it also captures screenshots, encoding and exfiltrating images through temporary files.

Upon confirming their foothold within the system, operators often proceed to enumerate Active Directory accounts and sensitive system configurations using standard command-line tools. This lateral movement is particularly concerning; the Node.js backdoor facilitates Windows Remote Management (WinRM) connections to additional systems within the network, including critical servers and databases. The reliance on WinRM via a user-context process represents a significant marker of high-level intrusion, indicating credential-backed remote execution has taken place.

As a countermeasure, organizations are encouraged to approach unsolicited external calls or Teams messages claiming to be from IT support with skepticism. Employees should verify such requests through internal communication channels. Moreover, limiting Microsoft Teams external collaboration to trusted domains can greatly mitigate risk.

Organizations are advised to closely monitor for specific activity indicators such as PowerShell executions following remote support sessions and unusual node.js activity. Enforcing multi-factor authentication (MFA), restricting WinRM to authorized management hosts, and ensuring robust endpoint protection can significantly diminish the potential for a deceptive Teams interaction to result in a widespread security breach.

In conclusion, organizations must remain vigilant in their cybersecurity practices to thwart such advanced intrusion methods. Microsoft recommends that if any signs of this type of malicious activity are detected, organizations should assume that broader network access has been compromised and take immediate steps to rotate credentials that may have been exposed. This proactive approach is critical in defending against increasingly sophisticated threats in today’s digital landscape.

Source link

Latest articles

Grindr Reaches £26 Million Settlement Over UK Data Privacy Claims

Grindr Settles £26 Million Lawsuit Over Misuse of Personal Data Grindr, the popular LGBTQ dating...

AI Agents May Decrease the Reliability of Human Oversight

Human Oversight at Risk Due to AI: Research Highlights Concerns of “Approval Fatigue” In an...

Mars Security Launches Automated Threat Engine for Rapid Cyber Intelligence Processing into Validated Rules

Mars Security Revolutionizes Threat Detection with Behavioral Mechanics In the ever-evolving landscape of cybersecurity, the...

CISA Advises Operators to Strengthen Siemens S7 PLCs: Strategies for Maintaining Production Continuity

Siemens S7 Controller Cybersecurity Advisory: A Cautionary Examination In the realm of industrial cybersecurity, the...

More like this

Grindr Reaches £26 Million Settlement Over UK Data Privacy Claims

Grindr Settles £26 Million Lawsuit Over Misuse of Personal Data Grindr, the popular LGBTQ dating...

AI Agents May Decrease the Reliability of Human Oversight

Human Oversight at Risk Due to AI: Research Highlights Concerns of “Approval Fatigue” In an...

Mars Security Launches Automated Threat Engine for Rapid Cyber Intelligence Processing into Validated Rules

Mars Security Revolutionizes Threat Detection with Behavioral Mechanics In the ever-evolving landscape of cybersecurity, the...