{"id":7505,"date":"2025-10-08T10:03:32","date_gmt":"2025-10-08T10:03:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/08\/microsoft-warns-of-hackers-abuse-teams-features-and-capabilities-to-deliver-malware\/"},"modified":"2025-10-08T10:03:32","modified_gmt":"2025-10-08T10:03:32","slug":"microsoft-warns-of-hackers-abuse-teams-features-and-capabilities-to-deliver-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/08\/microsoft-warns-of-hackers-abuse-teams-features-and-capabilities-to-deliver-malware\/","title":{"rendered":"Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware"},"content":{"rendered":"<p>    Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has issued a warning that both cybercriminals and state-sponsored threat actors are increasingly abusing the features and capabilities of Microsoft Teams throughout their attack chains.<\/p>\n<p>The extensive collaboration features and global adoption of <a href=\"https:\/\/cybersecuritynews.com\/tag\/microsoft-teams\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Teams<\/a> make it a high-value target for both cybercriminals and state-sponsored actors.<\/p>\n<p>Threat actors abuse its core capabilities, messaging (chat), calls, and meetings, and video-based screen-sharing at different points along the attack chain.<\/p>\n<p>This raises the stakes for defenders to proactively monitor, detect, and respond. While Microsoft\u2019s Secure Future Initiative (SFI) has strengthened default security, the company emphasizes that defenders must utilize available security controls to harden their enterprise Teams environments.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-hackers-abuse-teams-features\"><strong>Hackers Abuse Teams Features<\/strong><\/h2>\n<p>Attackers are leveraging the entire attack lifecycle within the Teams ecosystem, from initial reconnaissance to final impact, Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/10\/07\/disrupting-threats-targeting-microsoft-teams\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said<\/a>.<\/p>\n<p>This involves a multi-stage process where the platform\u2019s trusted status is exploited to infiltrate networks, steal data, and deploy malware.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiTvv7DIVMX698Yw5MeXm4X1siJKskCXsnEjAbyQRt7BVGnDhAfBk3ji7BXgJroC3PfC4e8yYeS7_3ClldyR0FEQG9Gl4wU_t4NizNyQyvo_4Kepo2Ur1AK2mt4_YdgWuT-0p5qsfk6CtfkjaBhgL86GUlYP093uPZPWA4aW8__gEKgRG8V4HQBLqUaWJni\/s16000\/Hackers%2520Abuse%2520Teams%2520Features.webp?ssl=1\" alt=\"Teams Attack Chain\"><figcaption class=\"wp-element-caption\">Teams Attack Chain<\/figcaption><\/figure>\n<p>The attack chain often begins with reconnaissance, where threat actors use open-source tools like TeamsEnum and TeamFiltration to enumerate users, groups, and tenants.<\/p>\n<p>They map organizational structures and identify security weaknesses, such as permissive external communication settings.<\/p>\n<p>This is followed by resource development, where attackers may compromise legitimate tenants or create new ones, complete with custom branding, to impersonate trusted entities like IT support.<\/p>\n<p>Once they have established a credible persona, attackers move to initial access. This stage frequently involves social engineering tactics such as tech support scams.<\/p>\n<p>For example, the threat actor <a href=\"https:\/\/cybersecuritynews.com\/rmm-tools-to-deliver-black-basta-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Storm-1811<\/a> has impersonated tech support to address fabricated email issues, using the pretext to deploy ransomware.<\/p>\n<p>Similarly, affiliates of the<a href=\"https:\/\/cybersecuritynews.com\/threeam-ransomware-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\"> 3AM ransomware<\/a> have flooded employees with junk email and then used Teams calls to convince them to grant remote access.<\/p>\n<p>Malicious links and payloads are also delivered directly through Teams chats, with tools like AADInternals and TeamsPhisher being used to distribute malware like <a href=\"https:\/\/cybersecuritynews.com\/tag\/darkgate-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">DarkGate<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-escalation-and-lateral-movement\"><strong>Escalation and Lateral Movement<\/strong><\/h2>\n<p>After gaining a foothold, threat actors focus on <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">maintaining persistence\u00a0and\u00a0escalating privileges<\/span>. They may add their own guest accounts, abuse device code authentication flows to steal access tokens, or use phishing lures to deliver malware that ensures long-term access.<\/p>\n<p>The financially motivated group Octo Tempest has been observed using aggressive <a href=\"https:\/\/cybersecuritynews.com\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> over Teams to compromise Multi-Factor Authentication (MFA) for privileged accounts.<\/p>\n<p>With elevated access, attackers begin discovery and lateral movement. They use tools like AzureHound to map the compromised organization\u2019s Microsoft Entra ID configuration and search for valuable data.<\/p>\n<p>The state-sponsored actor Peach Sandstorm has used Teams to deliver malicious ZIP files and then explored on-premises <a href=\"https:\/\/cybersecuritynews.com\/active-directory-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory<\/a> databases.<\/p>\n<p>If an attacker gains admin access, they can alter external communication settings to establish trust relationships with other organizations, enabling lateral movement between tenants.<\/p>\n<p>The final stages of the attack involve collection, <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">command and control (C2)<\/a>, exfiltration, and impact. Attackers use tools like GraphRunner to search and export sensitive conversations and files from Teams, OneDrive, and SharePoint.<\/p>\n<p>Some malware, like a cracked version of Brute Ratel C4 (BRc4), is designed to establish C2 channels using Teams\u2019 own communication protocols to send and receive commands.<\/p>\n<p>Data exfiltration can occur through Teams messages or shared links pointing to attacker-controlled cloud storage. The ultimate goal is often financial theft through extortion or ransomware.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/microsoft-unveils-playbook\/\" target=\"_blank\" rel=\"noreferrer noopener\">Octo Tempest<\/a>, for instance, has used Teams to send threatening messages to pressure organizations into making payments after successfully gaining control of their systems.<\/p>\n<p>This demonstrates how the platform can be abused not just as an entry vector, but as a tool for direct financial coercion.<\/p>\n<p>In response, experts recommend a defense-in-depth strategy, focusing on hardening identity and access controls, monitoring for anomalous activity within Teams, and providing continuous security awareness training to users.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code>Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: <a href=\"https:\/\/ethicalhacksacademy.com\/pages\/diamond-membership\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Join Today<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-teams-features\/\">Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-teams-features\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware Microsoft has issued a warning that both cybercriminals and state-sponsored threat actors are increasingly abusing the features and capabilities of Microsoft Teams throughout their attack chains. The extensive collaboration features and global adoption of Microsoft Teams make it a high-value target for both [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258],"tags":[130],"class_list":["post-7505","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7505"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7505"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7505\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}