← Back to feed
Threat Actors & CampaignsEmerging2 sourcesSep 2, 2026 · 22:51via Microsoft Security Blog

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Brief

In this article

  • Risk to enterprise environments
  • Attack chain overview
  • Mitigation and response recommendations
  • Learn more

Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session.

Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node. js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2).

Unlike commodity phishing that ends with an infostealer, this campaign follows a full hands-on-keyboard playbook.

Read more on Microsoft Security Blog

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Microsoft Security BlogPrimary··trust 1.36

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

In this article

  • Risk to enterprise environments
  • Attack chain overview
  • Mitigation and response recommendations
  • Learn more

Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session.

Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node. js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2).

Unlike commodity phishing that ends with an infostealer, this campaign follows a full hands-on-keyboard playbook.

After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim’s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers.

The intrusion relies heavily on legitimate tooling, including Microsoft Teams, remote support software, Windows Installer, Node. js, and native administrative protocols, allowing the activity to blend into expected enterprise operations at nearly every stage.

This intrusion pattern is especially high-impact because it hands an external operator credential-backed, interactive access to internal infrastructure.

Read more →
Malware.news··trust 0.88

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

In this article

  • Risk to enterprise environments
  • Attack chain overview
  • Mitigation and response recommendations
  • Learn more

Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session.

Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node. js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2).

Unlike commodity phishing that ends with an infostealer, this campaign follows a full hands-on-keyboard playbook.

After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim’s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers.

The intrusion relies heavily on legitimate tooling, including Microsoft Teams, remote support software, Windows Installer, Node. js, and native administrative protocols, allowing the activity to blend into expected enterprise operations at nearly every stage.

This intrusion pattern is especially high-impact because it hands an external operator credential-backed, interactive access to internal infrastructure.

Read more →