Summary
- Belgian reports involve criminals impersonating executives through Teams to request payments, credentials, or sensitive information.
- Microsoft separately observed attackers posing as IT support before persuading victims to grant remote-control sessions.
- The attacks abuse legitimate collaboration and support features rather than a vulnerability in Microsoft Teams.
Microsoft Teams is becoming a more prominent channel for impersonation attacks as criminals shift social engineering into collaboration workflows already used for internal support, management requests, and routine business communication.
Belgian authorities have received reports of criminals using Teams to impersonate chief executives, directors, shareholders, and other senior figures before seeking payments or sensitive information. Separately, Microsoft has documented a human-operated intrusion campaign in which attackers pose as IT support and persuade users to grant remote access to their computers.
The two activities are not established as one campaign. They instead demonstrate two ways the trust associated with an enterprise collaboration platform can be exploited for different objectives.
Executive impersonation is an extension of a well-established fraud model. Business email compromise has long relied on criminals posing as senior managers or suppliers to persuade employees to make payments, alter banking details, or disclose information.
Moving that conversation into Teams changes the context in which the request is received. Employees may associate the platform with internal communication and give an unexpected message a different level of trust from an unsolicited email.
Microsoft’s campaign goes further into technical compromise. Its threat intelligence team observed attackers operating from external Teams tenants while impersonating IT or helpdesk personnel. Victims were persuaded to accept a remote-control session through legitimate support functionality or tools such as Quick Assist.
Once interactive access was established, attackers used PowerShell to download and silently install a malicious MSI package. Microsoft observed the package staging a portable Node.js runtime and an obfuscated JavaScript implant capable of persistent command execution.
The attackers then performed host and Active Directory reconnaissance, captured screenshots, and used Windows Remote Management to move towards higher-value infrastructure, including domain controllers.
Microsoft says the activity does not exploit a vulnerability in Teams. The intrusion depends on convincing a user to override security warnings and voluntarily provide remote access through legitimate collaboration and support processes.
That makes the sequence harder to reduce to conventional phishing controls. Email gateways can inspect attachments, domains, and links, while a Teams conversation may begin without a malicious file or web address at all.
The same applies to remote-support software. Quick Assist and other administration tools have legitimate business uses, so their presence on an endpoint is not automatically suspicious. The risk emerges from the context in which the session was initiated and the actions that follow it.
Cross-tenant collaboration adds another layer. Organisations often allow external Teams communication because employees need to work with customers, suppliers, contractors, and partners. Restricting that capability can interfere with normal operations, but broad access also increases the number of external identities that can initiate apparently familiar conversations.
Microsoft has added external-contact labels, accept-or-block prompts, phishing indicators, and other controls around suspicious communications. Those protections still face a human decision when an attacker provides a convincing explanation for why the warnings should be ignored.
The emerging pattern extends identity risk beyond passwords. A criminal may obtain access simply by persuading someone with legitimate privileges to create the session on the attacker’s behalf.
As business communication moves further into collaboration platforms, fraud and intrusion activity is following it. The security question is increasingly whether the organisation can distinguish a genuine internal interaction from an attacker using the same legitimate communication and support functions.





