May 15, 2026
By esentry Team

Microsoft Teams Spoofing Vulnerability

The active exploitation of Microsoft Teams to conduct spoofing attacks and malware delivery campaigns, have been confirmed. Including incidents where attackers used hijacked Teams conversations to deploy ModeloRAT malware.

Unlike traditional phishing emails, this campaign abuses a trusted collaboration platform already embedded in daily business operations. The attack does not rely on software exploitation alone, it combines platform design behavior, default configuration exposure, and social engineering to bypass conventional security controls.

Attack Overview

Threat actors leveraged Microsoft Teams’ external communication capabilities to impersonate legitimate internal users or IT support personnel.

Attack flow observed across multiple reports:

  1. Attackers create or compromise external Microsoft 365 tenants.
  2. Using Teams external chat functionality, they initiate conversations with employees.
  3. Messages appear legitimate due to the trusted corporate collaboration environment.
  4. Victims are convinced to download files, approve access, or launch remote tools.
  5. Malware including ModeloRAT is deployed after access is established.  

Attackers used real Microsoft tools and workflows, allowing activity to blend into normal enterprise behaviour and evade detection.

Why This Happened

1. Default External Communication Settings

Many organizations allow communication with unknown external Teams tenants without restriction.

Attackers exploit this openness to directly reach employees.

2. Identity Trust Gap in Collaboration Platforms

Teams’ conversations inherently feel internal and safe. Users apply fewer security checks compared to email communications.

Collaboration platforms are now high-trust attack surfaces.

3. Legitimate Tool Abuse (Living-off-the-Land)

Attackers rely on signed Microsoft utilities including:

  • Microsoft Teams
  • Quick Assist
  • Native Windows administration tools  

Since no obvious malware initially executes, traditional controls may not trigger alerts.

Affected Environment

Exposure primarily affects:

  • Microsoft Teams Desktop Application
  • Microsoft Teams Web Application
  • Microsoft 365 Tenants with external chat enabled
  • Windows endpoints where remote assistance tools are permitted  

Organizations heavily dependent on Teams for internal collaboration are at increased risk.

Technical Indicators of Suspicious Activity

Security teams should monitor for:

  • External Teams users initiating unsolicited chats.
  • Messages claiming to originate from IT or security teams.
  • Requests to start remote support sessions.
  • Sudden Quick Assist sessions.
  • Unexpected file transfers via Teams.
  • Users executing scripts or installers shared through Teams chats.

Recommendations

1. Restrict External Teams Communication

  • Configure Teams Admin Center to allow communication only with approved domains.
  • Disable open federation where possible.

2. Enforce External User Visibility

  • Ensure external sender banners are clearly visible.
  • Prevent external users from appearing as internal identities.

3. Disable Unnecessary Remote Assistance Tools

  • Restrict or monitor:  
    • Microsoft Quick Assist
    • Remote desktop utilities
    • Remote admin execution without approval workflows

4. Implement Conditional Access Controls

  • Require device compliance before allowing Teams interaction.
  • Apply MFA enforcement for administrative or privileged roles.  

5. Monitor Collaboration Channels as Threat Vectors
Security monitoring should expand beyond email:

  • Log Teams chat initiation events.
  • Alert on external tenant communications.
  • Monitor abnormal user interaction patterns.

Organizations should treat collaboration tools as Tier-1 attack surfaces, equivalent to email gateways and internet-facing systems.