Connects to any signal across any vendor stack and powers adaptive AI Operatives that expose, detect, and neutralize cyberattacks.
Atlas Operations CenterSee what our SOC sees, review investigations, and see how we are protecting your business.
Technology IntegrationsAtlas connects to any signal across your current security tools. Whatever you're running, we're running with you.
Extend your team with immediate expertise, hands-on remediation, and the human accountability layer that boards, regulators, and cyber insurers require.
Threat Response UnitProactive threat intelligence, original threat research and a world-class team of seasoned industry veterans.
Response and RemediationPairs machine-speed containment with human judgment, delivering full threat response that's policy-bounded, reversible, and explainable.
MDR that moves first, multi-signal attack surface coverage, and 24/7 Elite threat hunters working as one continuous security program across any vendor stack.
Get unlimited Incident Response with threat suppression guarantee- anytime, anywhere.
Atlas Preempt deploys AI Operatives to continuously validate attack paths exposing attacker targets of opportunity before they take advantage.
Protect insurance operations from cyber attacks.
ConstructionSecure project data and jobsite operations.
FinanceDefend financial services from cyber disruption.
LegalSafeguard client data and legal operations.
ManufacturingStop threats before they disrupt production.
Private EquityProtect portfolio companies from cyber risk.
HealthcareDefend patient data and clinical operations.
RetailProtect customer data and retail operations.
Food SupplySecure the food supply chain from cyber threats.
Government and EducationProtect public sector and education systems.
Automotive DealershipsSecure dealership operations and customer data.
Stop ransomware before it spreads.
Identity ResponseStop identity-based cyberattacks.
Zero Day AttacksDetect and respond to zero-day exploits.
Cybersecurity ComplianceMeet regulatory compliance mandates.
Third-Party RiskDefend third-party and supply chain risk.
Cloud MisconfigurationEnd misconfigurations and policy violations.
Cyber RiskAdopt a risk-based security approach.
Mid-Market SecurityMid-market security essentials to prioritize.
Sensitive Data SecurityProtect your most sensitive data.
Cyber InsuranceMeet insurability requirements with MDR.
Cyber Threat IntelligenceOperationalize cyber threat intelligence.
Security LeadershipBuild a proven security program.
eSentire's Threat Response Unit (TRU) has continued to observe a sustained increase in attacks involving Microsoft Teams-based phishing and IT Support impersonation. These types of attacks…
On September 22nd, 2026, Check Point published a security advisory disclosing two critical vulnerabilities CVE-2026-93616 (CVSS: 9.8) and CVE-2026-85102 (CVSS: 9.8), affecting its Security…
eSentire is a leader in Controlled Autonomy SecOps, protecting 2,000+ organizations across 35+ industries around the world. Founded in 2001, the company’s Controlled Autonomy SecOps operating model pairs agentic AI operatives with engineered human-judgment controls, delivering expert-depth security outcomes at machine speed without ceding accountability to opaque automation.
About Us Leadership Careers Event Calendar → Newsroom → Aston Villa Football Club →We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Search our site
Multi-Signal MDR with 300+ technology integrations to support your existing investments.
24/7 SOC-as-a-Service with unlimited threat hunting and incident handling.
We offer three flexible MDR pricing packages that can be customized to your unique needs.
The latest security advisories, blogs, reports, industry publications and webinars published by TRU.
Compare eSentire to other Managed Detection and Response vendors to see how we stack up against the competition.
See why 2000+ organizations globally have chosen eSentire for their MDR Solution.
eSentire's Threat Response Unit (TRU) has continued to observe a sustained increase in attacks involving Microsoft Teams-based phishing and IT Support impersonation. These types of attacks involve threat actors contacting users over Microsoft Teams, posing as IT Support or a colleague, and attempting to trick users into granting remote access to their device through a Remote Monitoring and Management (RMM) tool. Observed cases have resulted in the deployment of Remote Access Trojans (RATs), information stealers, and backdoors, which can ultimately lead to data theft or ransomware.
To protect against this threat, organizations should restrict communication with external domains within Microsoft Teams, using allowlists for approved external domains as needed. Organizations should also educate users on this attack method and create internal processes for users to validate support requests through secondary channels.
Microsoft Teams IT support impersonation has become one of the most frequently observed attack types investigated by eSentire. Throughout most of 2025, only a small number of cases were observed each month. Activity increased in late 2025, accelerated in early 2026, and has remained consistently elevated since July 2026, with multiple new attempts observed daily. Current volume is more than twenty times higher than during the same period in 2025 and more than double the rate observed in the first half of 2026.

Manufacturing and legal services were the most frequently targeted industries over the last 90 days, accounting for 20% and 16% of incidents respectively, or more than a third of all cases. Law firms were notable for repeated targeting, with the same firms contacted on multiple occasions, and several attorneys or staff members often targeted in quick succession. Retail (9%), business services (8%), software (8%), and finance (7%) organizations were also frequently targeted, followed by insurance and construction.
Observed activity indicates coordinated campaigns rather than isolated attempts. Approximately one in seven cases involved multiple employees at the same organization within a short timeframe, and approximately 13% of observed attacker domains, email addresses, and IP addresses were used against more than one eSentire customer, including individual sending IP addresses observed across multiple organizations. In addition to IT support personas, threat actors are also impersonating colleagues or using generic display names to initiate contact.
Both IT support impersonation and generic display name approaches are closely associated with email bombing. In a number of cases, the targeted user's inbox was first flooded with spam or subscription emails, providing a pretext for the threat actor to make contact and offer assistance.
Following initial contact, threat actors often use Quick Assist to gain remote access, observed in nearly 60% of cases where a remote access tool or malware payload was identified, followed by AnyDesk, Atera, ScreenConnect, TeamViewer, Splashtop, SuperOps, Xeox, and GetScreen. In two cases analyzed, malware was deployed within one hour of the Quick Assist session being established. Secondary payloads observed include:
Many of these payloads execute through legitimate runtimes (Node.js, Deno, Python, Java) placed in the user's profile, which can reduce detection by signature-based controls.
Several observed payloads have documented links to ransomware operations. Edgecution, observed in multiple cases between late June and early August 2026, is used by UNC6692, an Initial Access Broker (IAB) that follows the same email bombing, Microsoft Teams, and Quick Assist playbook and sells access to the Payouts King ransomware operation. One July 2026 case was directly linked to Payouts King. Nimbus RAT has been associated with BlackSuit ransomware affiliates.

Threat actors rely on disposable infrastructure, including help desk-themed domains, newly created Microsoft 365 tenants, and VPN and hosting IP addresses that are rotated once blocked. The indicators below are a sample from recent cases; eSentire maintains a larger, regularly updated blocklist.
eSentire assesses with moderate to high confidence that Microsoft Teams-based impersonation will remain one of the most common initial access techniques through the end of 2026. The technique requires minimal investment, does not require malware for initial contact, and exploits external collaboration settings that many organizations leave enabled. As organizations restrict external access and block newly created tenants, threat actors are expected to shift toward compromised legitimate tenants and consumer accounts, extend the same approach to phone calls, SMS, and other collaboration platforms, and replace Quick Assist with less common remote access tools or built-in screen sharing features. Professional services organizations that collaborate extensively with external parties, including law firms, are likely to remain at priority targets.
References:
[1] https://www.esentire.com/security-advisories/increase-in-email-bombing-and-it-impersonation-campaigns
[2] https://www.esentire.com/blog/email-bombing-it-impersonation-quick-assist-and-edgecution-breaking-down-unc6692s-tradecraft
[3] https://www.esentire.com/blog/trust-me-im-it-threat-actors-deliver-deno-based-backdoor-denogate-via-microsoft-teams
[4] https://www.esentire.com/blog/nimbus-rat-how-threat-actors-are-abusing-microsoft-teams-and-google-drive-to-deploy-a-java-rat
[5] https://www.esentire.com/blog/etherrat-sys-info-module-c2-on-ethereum-etherhiding-target-selection-cdn-like-beacons
[6] https://www.esentire.com/blog/new-botnet-emerges-from-the-shadows-nightshadec2
[7] https://www.esentire.com/blog/muddywater-apt-tsundere-botnet-etherhiding-the-c2
[8] https://www.esentire.com/resources/library/esentire-2026-annual-cyber-threat-report
[9] https://www.esentire.com/what-we-do/threat-response-unit/threat-intelligence-services
[10] https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
[11] https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/
[12] https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/
[13] https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing
[14] https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/
[15] https://learn.microsoft.com/en-us/microsoftteams/trusted-organizations-external-meetings-chat