Security advisories

Surge in Microsoft Teams-Based Phishing and IT Support Impersonation

September 25, 2026

7 MINS READ

THE THREAT

eSentire's Threat Response Unit (TRU) has continued to observe a sustained increase in attacks involving Microsoft Teams-based phishing and IT Support impersonation. These types of attacks involve threat actors contacting users over Microsoft Teams, posing as IT Support or a colleague, and attempting to trick users into granting remote access to their device through a Remote Monitoring and Management (RMM) tool. Observed cases have resulted in the deployment of Remote Access Trojans (RATs), information stealers, and backdoors, which can ultimately lead to data theft or ransomware.

To protect against this threat, organizations should restrict communication with external domains within Microsoft Teams, using allowlists for approved external domains as needed. Organizations should also educate users on this attack method and create internal processes for users to validate support requests through secondary channels.

What We're Doing About It

What You Should Do About It

Additional Information

Microsoft Teams IT support impersonation has become one of the most frequently observed attack types investigated by eSentire. Throughout most of 2025, only a small number of cases were observed each month. Activity increased in late 2025, accelerated in early 2026, and has remained consistently elevated since July 2026, with multiple new attempts observed daily. Current volume is more than twenty times higher than during the same period in 2025 and more than double the rate observed in the first half of 2026.

Figure 1 – Monthly Microsoft Teams IT support impersonation incidents investigated by eSentire, May 2025 - September 2026
Figure 1 – Monthly Microsoft Teams IT support impersonation incidents investigated by eSentire, May 2025 - September 2026

Manufacturing and legal services were the most frequently targeted industries over the last 90 days, accounting for 20% and 16% of incidents respectively, or more than a third of all cases. Law firms were notable for repeated targeting, with the same firms contacted on multiple occasions, and several attorneys or staff members often targeted in quick succession. Retail (9%), business services (8%), software (8%), and finance (7%) organizations were also frequently targeted, followed by insurance and construction.

Observed activity indicates coordinated campaigns rather than isolated attempts. Approximately one in seven cases involved multiple employees at the same organization within a short timeframe, and approximately 13% of observed attacker domains, email addresses, and IP addresses were used against more than one eSentire customer, including individual sending IP addresses observed across multiple organizations. In addition to IT support personas, threat actors are also impersonating colleagues or using generic display names to initiate contact.

Both IT support impersonation and generic display name approaches are closely associated with email bombing. In a number of cases, the targeted user's inbox was first flooded with spam or subscription emails, providing a pretext for the threat actor to make contact and offer assistance.

Following initial contact, threat actors often use Quick Assist to gain remote access, observed in nearly 60% of cases where a remote access tool or malware payload was identified, followed by AnyDesk, Atera, ScreenConnect, TeamViewer, Splashtop, SuperOps, Xeox, and GetScreen. In two cases analyzed, malware was deployed within one hour of the Quick Assist session being established. Secondary payloads observed include:

Many of these payloads execute through legitimate runtimes (Node.js, Deno, Python, Java) placed in the user's profile, which can reduce detection by signature-based controls.

Several observed payloads have documented links to ransomware operations. Edgecution, observed in multiple cases between late June and early August 2026, is used by UNC6692, an Initial Access Broker (IAB) that follows the same email bombing, Microsoft Teams, and Quick Assist playbook and sells access to the Payouts King ransomware operation. One July 2026 case was directly linked to Payouts King. Nimbus RAT has been associated with BlackSuit ransomware affiliates.

Figure 2 – Remote access tools and malware seen in MS Teams IT support impersonation cases investigated by eSentire, September 2025 - September 2026
Figure 2 – Remote access tools and malware seen in MS Teams IT support impersonation cases investigated by eSentire, September 2025 - September 2026

Threat actors rely on disposable infrastructure, including help desk-themed domains, newly created Microsoft 365 tenants, and VPN and hosting IP addresses that are rotated once blocked. The indicators below are a sample from recent cases; eSentire maintains a larger, regularly updated blocklist.

eSentire assesses with moderate to high confidence that Microsoft Teams-based impersonation will remain one of the most common initial access techniques through the end of 2026. The technique requires minimal investment, does not require malware for initial contact, and exploits external collaboration settings that many organizations leave enabled. As organizations restrict external access and block newly created tenants, threat actors are expected to shift toward compromised legitimate tenants and consumer accounts, extend the same approach to phone calls, SMS, and other collaboration platforms, and replace Quick Assist with less common remote access tools or built-in screen sharing features. Professional services organizations that collaborate extensively with external parties, including law firms, are likely to remain at priority targets.

Indicators of Compromise (IOCs)
Indicator Type
helpdesk-support-office-4[.]com Domain
system-guard[.]top Domain
get-help-service[.]top Domain
supportexpert[.]top Domain
sqaservice[.]onmicrosoft[.]com Domain (Teams tenant)
it[.]helpdesk[@]ltdatransliquidos[.]onmicrosoft[.]com Email (Teams sender)
192[.]142[.]46[.]120 IPv4 (sender)
162[.]35[.]163[.]94 IPv4 (sender)
209[.]200[.]246[.]82 IPv4 (sender)
2[.]58[.]14[.]77 IPv4 (sender)

References:

[1] https://www.esentire.com/security-advisories/increase-in-email-bombing-and-it-impersonation-campaigns
[2] https://www.esentire.com/blog/email-bombing-it-impersonation-quick-assist-and-edgecution-breaking-down-unc6692s-tradecraft
[3] https://www.esentire.com/blog/trust-me-im-it-threat-actors-deliver-deno-based-backdoor-denogate-via-microsoft-teams
[4] https://www.esentire.com/blog/nimbus-rat-how-threat-actors-are-abusing-microsoft-teams-and-google-drive-to-deploy-a-java-rat
[5] https://www.esentire.com/blog/etherrat-sys-info-module-c2-on-ethereum-etherhiding-target-selection-cdn-like-beacons
[6] https://www.esentire.com/blog/new-botnet-emerges-from-the-shadows-nightshadec2
[7] https://www.esentire.com/blog/muddywater-apt-tsundere-botnet-etherhiding-the-c2
[8] https://www.esentire.com/resources/library/esentire-2026-annual-cyber-threat-report
[9] https://www.esentire.com/what-we-do/threat-response-unit/threat-intelligence-services
[10] https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
[11] https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/
[12] https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/
[13] https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing
[14] https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/
[15] https://learn.microsoft.com/en-us/microsoftteams/trusted-organizations-external-meetings-chat

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories