Rapid7 Guidance on Observed Microsoft Teams Phishing Campaigns
2026-03-16T19:23:55Z•1058aa98c5b4fdee38d10fab154a4152f2a9f4cbc8de92aef265dce8ed517145
collaboration-toolsdata-exfiltrationexternal-user-messagingit-support-impersonationlateral-movementmalware-deploymentmicrosoft-teamsphishingquick-assistremote-accesssocial-engineeringspoofing
What happened
Rapid7 observed an increase in Microsoft Teams–based phishing campaigns where attackers spoof internal IT (e.g., “IT Support” or “System Admin”) to socially engineer users into launching Windows Quick Assist. The typical chain: mass spoofed chat requests from external accounts → active engagement posing as IT support → persuasion to start Quick Assist (granting remote control) → use of remote access to deploy malware, exfiltrate data, and perform lateral movement. The campaigns exploit collaboration-platform trust and the ability for external users to message internal staff (the subtle “Extern
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 1058aa98c5b4fdee38d10fab154a4152f2a9f4cbc8de92aef265dce8ed517145
- Enrichment time
- 2026-03-16T19:23:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.