Rapid7 Guidance on Observed Microsoft Teams Phishing Campaigns

2026-03-16T19:23:55Z1058aa98c5b4fdee38d10fab154a4152f2a9f4cbc8de92aef265dce8ed517145
collaboration-toolsdata-exfiltrationexternal-user-messagingit-support-impersonationlateral-movementmalware-deploymentmicrosoft-teamsphishingquick-assistremote-accesssocial-engineeringspoofing

What happened

Rapid7 observed an increase in Microsoft Teams–based phishing campaigns where attackers spoof internal IT (e.g., “IT Support” or “System Admin”) to socially engineer users into launching Windows Quick Assist. The typical chain: mass spoofed chat requests from external accounts → active engagement posing as IT support → persuasion to start Quick Assist (granting remote control) → use of remote access to deploy malware, exfiltrate data, and perform lateral movement. The campaigns exploit collaboration-platform trust and the ability for external users to message internal staff (the subtle “Extern

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
1058aa98c5b4fdee38d10fab154a4152f2a9f4cbc8de92aef265dce8ed517145
Enrichment time
2026-03-16T19:23:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.