Cybercriminals Impersonate IT Support on Microsoft Teams
Malicious actors are masquerading as IT professionals on Microsoft Teams, successfully convincing employees to relinquish control of their Windows computers.
This insidious campaign transforms a customary support dialogue into a direct conduit for installing malware, effectively granting the intruder operational access to the victim’s device as if they were physically present.
The assault initiates with an external Teams contact, wherein the operator cultivates trust before instructing the target to launch Windows Quick Assist.
Upon receiving session approval from the user, the assailant can discreetly download and execute a harmful installer, eluding the necessity to exploit software vulnerabilities or pilfer login credentials beforehand.
Unit 42 analysts classified this activity as a fraudulent help-desk operation that synergizes social engineering, the misuse of remote-control tools, and a clandestine command channel.
Unit 42, in a report shared with Cyber Security News (CSN), indicated that this method ultimately endows operators with interactive access for reconnaissance, paving the way for subsequent data theft or network breaches.
This campaign’s significance lies in its exploitation of tools and services that many organizations already endorse.
A seemingly innocuous Teams message, the integrated remote assistance capability, and cloud infrastructure traffic lend an air of legitimacy to the activity, rendering it less suspicious than conventional malware distribution approaches. This dynamic places an acute security decision squarely in the hands of an individual employee.
Impersonation Tactics on Microsoft Teams
The imposters feign IT expertise, utilizing Teams’ external access to target unsuspecting employees, directing them to Quick Assist—a legitimate Windows utility intended for authentic assistance—while soliciting approval for a remote session.
Similar Teams support call breaches illustrate the necessity of verifying unforeseen requests for remote assistance through a recognized internal channel, rather than complying with the caller’s directives.
Upon seizing control, the operator retrieves an MSI installer from an assailant-managed Amazon S3 bucket and executes it via Windows Installer.
The installer often adopts a name resembling a routine update, disguising a legitimate signed application alongside a malevolent supplementary file.
This tactic is emblematic of an extensive trend involving malware delivery via Teams, wherein ostensibly trustworthy workplace platforms are exploited to lower the guard of victims.
When the genuine program activates, it surreptitiously loads the adjacent malicious DLL instead of the standard Windows copy—an action known as DLL sideloading, which permits harmful code to operate under the guise of a validated application.
The DLL establishes an encrypted connection to an AWS API Gateway endpoint, showcasing how attackers can obscure command traffic within the parameters of ordinary cloud service interactions.
Concealed Shell Evades Detection
The sideloaded DLL itself does not directly furnish the assailant with the ultimate command prompt. Rather, it employs Windows Management Instrumentation (WMI) to launch a separate reverse-shell program.
This decoupled structure undermines simple process-tree scrutiny since the nefarious shell is not activated directly by the signed loader—a stratagem also observed in more recent DLL sideloading endeavors.
The malicious shell exclusively listens on the infected computer’s local address while exchanging data with the DLL, which maintains the external connection.
Subsequently, it unveils a hidden command prompt that attackers utilize to inspect the logged-in user, network configurations, domain accounts, and device registrations.
This group can also scrutinize cloud-synced document repositories, thereby posing an immediate risk to sensitive corporate data and personal identity information.
Defenders should impose restrictions or meticulously oversee Teams interactions from untrusted external accounts, clearly stating that IT personnel will not solicit Quick Assist access through unsolicited chats or calls.
Organizations ought to reassess the necessity of Quick Assist, educate employees on independently verifying support requests, and meticulously investigate unusual remote session activities.
Advisories stemming from Microsoft Teams vishing tactics emphasize that a demand to initiate remote-support software warrants the same scrutiny as a suspicious attachment.
Security teams should remain vigilant for instances of signed applications loading unsigned DLLs from their own directories, unexpected WMI-spawned processes, and atypical local listeners.
Furthermore, they should scrutinize outbound encrypted connections emanating from trusted programs to execute API endpoints, particularly when a child process initiates system discovery.
By correlating these anomalies with prior external Teams contact and Quick Assist activities, enterprises can unveil the operation during its nascent stages of compromise.

Indicators of Compromise (IoCs):
- Domain:
0q8jnro0za.execute-api.us-east-1.amazonaws[.]com– AWS API Gateway command-and-control endpoint - Domain:
qqcy5av2o2.execute-api.us-east-1.amazonaws[.]com– AWS API Gateway command-and-control endpoint - Domain:
l9iprxgup2.execute-api.us-east-1.amazonaws[.]com– AWS API Gateway command-and-control endpoint - Domain:
9stbnu0f0a.execute-api.us-east-1.amazonaws[.]com– AWS API Gateway command-and-control endpoint - Domain:
software-download-usw1.s3.us-west-1.amazonaws[.]com– Attacker-controlled S3 payload host - URL:
hxxps[:]//software-download-usw1.s3.us-west-1.amazonaws[.]com/SE15724BW.msi– Malicious MSI download - SHA-256:
878567e4b6f4552f8f56f300c3a2af0fe9c7935686ee0e34ef5f632c81baa579– Trojanized Kodi MSI installer - SHA-256:
1423084a8aaa721627f9674fd4ba3679b27acdc7992001b91adb41f0457756b5– Trojanized Kodi MSI installer - SHA-256:
0112620b7fd940846bac876a9f8a148a7435d34fe0b596edf165325a81efb5b3– Maliciousvcruntime140.dllvariant - SHA-256:
6b5a6817d6fce0348ac1f4ef38298b57a00c8a8c3f3ca39335ca06a7b861f1d0– Maliciousvcruntime140_1.dllvariant - SHA-256:
3759aaaea1e9f6228e2701c415882f38ceb3e03b211e82600a6f31c68a4370ba– Maliciousvcruntime140.dllvariant - SHA-256:
c1bbbac9f501712db13f276d88a17277284e3684b690b33abd3508ef56064860– Maliciouszlib1.dllvariant - SHA-256:
74fdbe5d2a8b68a145cc79f75432fa8dd4dc71383040873929fca5f8a4f9229a– Maliciouszlib1.dllvariant - SHA-256:
26e3f1359ed228d9d4931b853f1bfc768c2ca22cb28b96c29380c040940c3a1f– Maliciouszlib1.dllvariant - SHA-256:
25b4cb9b9ff68487af37fb86b16b6e335d862821fa3749f860933c35013de509–File Transfer.execustom reverse-shell agent - SHA-256:
7499df565f74bd9d0ad69b1363217d57a65db7a9d4693e6e387b3841458477d7–SupportHost.execustom reverse-shell agent - SHA-256:
c44af51e75b2023376cf7fa2735d72f1c433d9dc58163dc298690731c80bc7f9–Module Agent.execustom reverse-shell agent - SHA-256:
fef16f362aa405ab83fe7e7f34948c3b062df9d0701eb883f7834301562fe0ae–kodi.exebinary abused for sideloading - SHA-256:
55bc7d960205ae3265a1bab47bbfa36a774dfe8e8eb4a80c2b78f625e758ba02–salamand.exebinary abused for sideloading - SHA-256:
Ff5ee21e81a38b959d2f4cd275dbf7a778dc72fd0becfdde80ef3f619d0f8b8b–filezilla.exeBinary abused for sideloading - File name:
SE15724BW.msi– Malicious MSI installer - File name:
KB5094126.msi– Malicious MSI installer - File name:
vcruntime140.dll– Malicious sideloaded DLL - File name:
vcruntime140_1.dll– Malicious sideloaded DLL - File name:
zlib1.dll– Malicious sideloaded DLL - File name:
File Transfer.exe– Custom reverse-shell agent - File name:
Module Agent.exe– Custom reverse-shell agent - File name:
SupportHost.exe– Custom reverse-shell agent - File name:
salamand.lnk– Startup-folder persistence shortcut - Network listener:
127.0.0.1:9001– Local TCP relay listener used to bridge command traffic - Mutex:
Global\\ConsoleMutex– Mutex utilized by the reverse-shell agent
Source link: Cybersecuritynews.com.






