Affected Systems
Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist.
Exploitation Status
Active exploitation confirmed. Microsoft Threat Intelligence has observed this human-operated intrusion campaign in the wild. Attackers are using social engineering via Teams to gain remote access, deploy Node.js implants, and perform lateral movement toward domain controllers.
Business Impact
High-impact intrusion pathway that grants external attackers credential-backed, interactive access to internal infrastructure. Observed activity includes Active Directory reconnaissance, WinRM-based lateral movement to domain controllers and certificate authorities, and desktop screen capture. Attack pattern is consistent with precursor activity for ransomware deployment, data exfiltration, or extortion operations. Relies on legitimate tools (Teams, RMM software, Node.js, WinRM, msiexec) making detection difficult without behavioral monitoring.
Urgency
🟠 Within 24 hours
Recommended Actions
- Configure Microsoft Teams to restrict or block external access from unknown tenants; review and enforce external collaboration policies organization-wide.
- Deploy endpoint detection rules for silent MSI installations via msiexec with network download sources, and monitor for Node.js execution from user-writable directories (e.g., %LOCALAPPDATA%).
- Enable WinRM logging and alert on outbound WinRM connections (TCP 5985) from workstations to servers, especially targeting domain controllers or certificate authorities.
- Conduct user awareness training focused on verifying IT support requests through out-of-band channels before granting remote access via Quick Assist, Teams screen sharing, or third-party RMM tools.
- Hunt for ADSI-based domain enumeration activity, PowerShell download cradles, and rundll32 execution of unsigned DLLs from temporary or user directories.
