Hackers Pose as IT Support on Microsoft Teams to Take Remote Control of Windows PCs
Brief
Cybercriminals are posing as IT technicians on Microsoft Teams and persuading employees to hand over control of their Windows computers.
The campaign turns a familiar support conversation into a direct path for installing malware, leaving the intruder able to work on the victim’s device as if sitting in front of it.
The attack begins through external Teams contact, where an operator builds trust and asks the target to open Windows Quick Assist.
Once the user approves the session, the attacker can download and launch a harmful installer, bypassing the need to exploit a software flaw or steal a password first.
Unit 42 analysts identified the activity as a fake help-desk operation that combines social engineering, remote-control abuse and a hidden command channel.
