Cybersecurity News: Cybercriminals Impersonate IT Support on Microsoft Teams to Seize Control of Windows Computers

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Cybercriminals Impersonate IT Support on Microsoft Teams

Malicious actors are masquerading as IT professionals on Microsoft Teams, successfully convincing employees to relinquish control of their Windows computers.

This insidious campaign transforms a customary support dialogue into a direct conduit for installing malware, effectively granting the intruder operational access to the victim’s device as if they were physically present.

The assault initiates with an external Teams contact, wherein the operator cultivates trust before instructing the target to launch Windows Quick Assist.

Upon receiving session approval from the user, the assailant can discreetly download and execute a harmful installer, eluding the necessity to exploit software vulnerabilities or pilfer login credentials beforehand.

Unit 42 analysts classified this activity as a fraudulent help-desk operation that synergizes social engineering, the misuse of remote-control tools, and a clandestine command channel.

Unit 42, in a report shared with Cyber Security News (CSN), indicated that this method ultimately endows operators with interactive access for reconnaissance, paving the way for subsequent data theft or network breaches.

This campaign’s significance lies in its exploitation of tools and services that many organizations already endorse.

A seemingly innocuous Teams message, the integrated remote assistance capability, and cloud infrastructure traffic lend an air of legitimacy to the activity, rendering it less suspicious than conventional malware distribution approaches. This dynamic places an acute security decision squarely in the hands of an individual employee.

Impersonation Tactics on Microsoft Teams

The imposters feign IT expertise, utilizing Teams’ external access to target unsuspecting employees, directing them to Quick Assist—a legitimate Windows utility intended for authentic assistance—while soliciting approval for a remote session.

Similar Teams support call breaches illustrate the necessity of verifying unforeseen requests for remote assistance through a recognized internal channel, rather than complying with the caller’s directives.

Upon seizing control, the operator retrieves an MSI installer from an assailant-managed Amazon S3 bucket and executes it via Windows Installer.

The installer often adopts a name resembling a routine update, disguising a legitimate signed application alongside a malevolent supplementary file.

This tactic is emblematic of an extensive trend involving malware delivery via Teams, wherein ostensibly trustworthy workplace platforms are exploited to lower the guard of victims.

When the genuine program activates, it surreptitiously loads the adjacent malicious DLL instead of the standard Windows copy—an action known as DLL sideloading, which permits harmful code to operate under the guise of a validated application.

The DLL establishes an encrypted connection to an AWS API Gateway endpoint, showcasing how attackers can obscure command traffic within the parameters of ordinary cloud service interactions.

Concealed Shell Evades Detection

The sideloaded DLL itself does not directly furnish the assailant with the ultimate command prompt. Rather, it employs Windows Management Instrumentation (WMI) to launch a separate reverse-shell program.

This decoupled structure undermines simple process-tree scrutiny since the nefarious shell is not activated directly by the signed loader—a stratagem also observed in more recent DLL sideloading endeavors.

The malicious shell exclusively listens on the infected computer’s local address while exchanging data with the DLL, which maintains the external connection.

Subsequently, it unveils a hidden command prompt that attackers utilize to inspect the logged-in user, network configurations, domain accounts, and device registrations.

This group can also scrutinize cloud-synced document repositories, thereby posing an immediate risk to sensitive corporate data and personal identity information.

Defenders should impose restrictions or meticulously oversee Teams interactions from untrusted external accounts, clearly stating that IT personnel will not solicit Quick Assist access through unsolicited chats or calls.

Organizations ought to reassess the necessity of Quick Assist, educate employees on independently verifying support requests, and meticulously investigate unusual remote session activities.

Advisories stemming from Microsoft Teams vishing tactics emphasize that a demand to initiate remote-support software warrants the same scrutiny as a suspicious attachment.

Security teams should remain vigilant for instances of signed applications loading unsigned DLLs from their own directories, unexpected WMI-spawned processes, and atypical local listeners.

Furthermore, they should scrutinize outbound encrypted connections emanating from trusted programs to execute API endpoints, particularly when a child process initiates system discovery.

By correlating these anomalies with prior external Teams contact and Quick Assist activities, enterprises can unveil the operation during its nascent stages of compromise.

Modern Microsoft office building with large logo, glass facade, and people walking outside in an urban business setting.

Indicators of Compromise (IoCs):

  • Domain: 0q8jnro0za.execute-api.us-east-1.amazonaws[.]com – AWS API Gateway command-and-control endpoint
  • Domain: qqcy5av2o2.execute-api.us-east-1.amazonaws[.]com – AWS API Gateway command-and-control endpoint
  • Domain: l9iprxgup2.execute-api.us-east-1.amazonaws[.]com – AWS API Gateway command-and-control endpoint
  • Domain: 9stbnu0f0a.execute-api.us-east-1.amazonaws[.]com – AWS API Gateway command-and-control endpoint
  • Domain: software-download-usw1.s3.us-west-1.amazonaws[.]com – Attacker-controlled S3 payload host
  • URL: hxxps[:]//software-download-usw1.s3.us-west-1.amazonaws[.]com/SE15724BW.msi – Malicious MSI download
  • SHA-256: 878567e4b6f4552f8f56f300c3a2af0fe9c7935686ee0e34ef5f632c81baa579 – Trojanized Kodi MSI installer
  • SHA-256: 1423084a8aaa721627f9674fd4ba3679b27acdc7992001b91adb41f0457756b5 – Trojanized Kodi MSI installer
  • SHA-256: 0112620b7fd940846bac876a9f8a148a7435d34fe0b596edf165325a81efb5b3 – Malicious vcruntime140.dll variant
  • SHA-256: 6b5a6817d6fce0348ac1f4ef38298b57a00c8a8c3f3ca39335ca06a7b861f1d0 – Malicious vcruntime140_1.dll variant
  • SHA-256: 3759aaaea1e9f6228e2701c415882f38ceb3e03b211e82600a6f31c68a4370ba – Malicious vcruntime140.dll variant
  • SHA-256: c1bbbac9f501712db13f276d88a17277284e3684b690b33abd3508ef56064860 – Malicious zlib1.dll variant
  • SHA-256: 74fdbe5d2a8b68a145cc79f75432fa8dd4dc71383040873929fca5f8a4f9229a – Malicious zlib1.dll variant
  • SHA-256: 26e3f1359ed228d9d4931b853f1bfc768c2ca22cb28b96c29380c040940c3a1f – Malicious zlib1.dll variant
  • SHA-256: 25b4cb9b9ff68487af37fb86b16b6e335d862821fa3749f860933c35013de509File Transfer.exe custom reverse-shell agent
  • SHA-256: 7499df565f74bd9d0ad69b1363217d57a65db7a9d4693e6e387b3841458477d7SupportHost.exe custom reverse-shell agent
  • SHA-256: c44af51e75b2023376cf7fa2735d72f1c433d9dc58163dc298690731c80bc7f9Module Agent.exe custom reverse-shell agent
  • SHA-256: fef16f362aa405ab83fe7e7f34948c3b062df9d0701eb883f7834301562fe0aekodi.exe binary abused for sideloading
  • SHA-256: 55bc7d960205ae3265a1bab47bbfa36a774dfe8e8eb4a80c2b78f625e758ba02salamand.exe binary abused for sideloading
  • SHA-256: Ff5ee21e81a38b959d2f4cd275dbf7a778dc72fd0becfdde80ef3f619d0f8b8bfilezilla.exe Binary abused for sideloading
  • File name: SE15724BW.msi – Malicious MSI installer
  • File name: KB5094126.msi – Malicious MSI installer
  • File name: vcruntime140.dll – Malicious sideloaded DLL
  • File name: vcruntime140_1.dll – Malicious sideloaded DLL
  • File name: zlib1.dll – Malicious sideloaded DLL
  • File name: File Transfer.exe – Custom reverse-shell agent
  • File name: Module Agent.exe – Custom reverse-shell agent
  • File name: SupportHost.exe – Custom reverse-shell agent
  • File name: salamand.lnk – Startup-folder persistence shortcut
  • Network listener: 127.0.0.1:9001 – Local TCP relay listener used to bridge command traffic
  • Mutex: Global\\ConsoleMutex – Mutex utilized by the reverse-shell agent

Source link: Cybersecuritynews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Neil Hemmings

I'm Neil Hemmings from Anaheim, CA, with an Associate of Science in Computer Science from Diablo Valley College. As Senior Tech Associate and Content Manager at RS Web Solutions, I write about AI, gadgets, cybersecurity, and apps – sharing hands-on reviews, tutorials, and practical tech insights.
Share the Love
Related News Worth Reading