$ techbeacon▋
CVE & Exploits

Cybercriminals Exploit Microsoft Teams Guest Chat to Mimic IT Support and Harvest Passwords

Cybercriminals Exploit Microsoft Teams Guest Chat to Mimic IT Support and Harvest Passwords

Cybercriminals are increasingly leveraging Microsoft Teams' external chat function to pose as corporate IT help desks, a tactic that has led to a surge in credential theft and unauthorized remote access across a range of organizations.

The scheme relies on Teams' ability to communicate with users outside an organization’s tenant. Attackers create guest accounts, add them to team channels, and then initiate conversations that appear to come from internal support staff. By presenting themselves as legitimate technicians, they persuade employees to click malicious links, download seemingly benign utilities, or grant screen‑sharing privileges.

Technical analysts note that the attack exploits a configuration weakness rather than a software flaw: many companies leave the external‑chat setting enabled without restricting who can add guests or without requiring additional verification. Once a guest is accepted, the attacker can send files that install remote‑access tools or keyloggers, capturing Windows credentials the moment the user logs in.

Victims who follow the fraudulent instructions often find that their machines are silently monitored, allowing threat actors to harvest usernames, passwords, and, in some cases, privileged accounts. The stolen data can be used to move laterally within the network, exfiltrate sensitive files, or sell the credentials on underground markets, amplifying the risk to both the individual employee and the broader enterprise.

The rise of this tactic coincides with the broader shift toward remote and hybrid work, where collaboration platforms like Teams have become essential. As organizations have accelerated digital transformation, attackers have adapted, targeting the very tools that enable remote productivity. Security researchers have flagged the approach as a sophisticated form of social engineering that blends technical exploitation with human manipulation.

Microsoft has responded by issuing guidance that urges administrators to review guest‑access policies, enforce multi‑factor authentication for external users, and educate staff on how to verify IT requests through independent channels. The company also recommends monitoring for unusual guest‑addition activity and disabling external chat where it is not required.

Security experts emphasize that the simplest defense remains user awareness: employees should treat any unsolicited request for credentials, software installation, or screen sharing with skepticism and confirm the request through known, official IT support channels before taking action.

In the wake of these incidents, several firms are tightening their Teams governance, deploying stricter conditional‑access rules, and integrating third‑party monitoring solutions that flag anomalous guest behavior. Such measures aim to reduce the attack surface while preserving the collaborative benefits of the platform.

As threat actors continue to refine their use of legitimate communication tools for illicit ends, organizations must balance openness with vigilance, ensuring that the convenience of external collaboration does not become a conduit for credential compromise.

Source: GBHackers
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related