← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 2, 2026 · 07:41via CyberPress

Fake IT Support Hackers Abuse Microsoft Teams and Quick Assist to Deploy Reverse Shell

Brief

Threat actors are using fake IT support requests on Microsoft Teams to trick employees into granting remote access through Quick Assist, then deploying a multi-stage reverse shell designed to blend into normal Windows activity.

Researchers Ofek Lahiani and Raz Rubin reported that the campaign begins with social engineering. Attackers contact targets through external Microsoft Teams chats while posing as IT technicians.

They convince victims that a technical problem requires remote support and instruct them to open Microsoft’s legitimate Quick Assist application.

Once the victim grants access, the attacker has hands-on control of the device. The operator downloads a malicious MSI installer from an attacker-controlled Amazon S3 bucket and runs it using msiexec. exe .

Observed installer names include SE15724BW. msi and KB5094126. msi .

Read more on CyberPress