Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Strategic summary
Microsoft Threat Intelligence observed a campaign that abuses Microsoft Teams external collaboration to impersonate IT support and trick users into granting an interactive remote session. After remote access is established through legitimate RMM tools, PowerShell downloads and installs a malicious MSI package that stages a portable Node.js runtime and an obfuscated JavaScript implant for persistent command execution and C2. Post-infection activity includes extensive host and Active Directory reconnaissance, periodic screenshots, and lateral movement via WinRM toward domain controllers. The campaign relies almost entirely on legitimate tooling and can precede data theft, extortion, or ransomware.
Key findings
- Attackers abuse Microsoft Teams to impersonate IT support and convince users to grant an interactive remote session.
- PowerShell downloads and installs a malicious MSI package that stages a portable Node.js runtime and an obfuscated JavaScript implant for persistent C2 communication.
- After installation, the threat actor performs host and Active Directory reconnaissance, captures periodic screenshots, and moves laterally via WinRM to high-value assets such as domain controllers.
- The attack chain relies on legitimate tools including Teams, remote support software, Windows Installer, and native administrative protocols, allowing it to blend into normal enterprise operations.
- The access enables external actors to map the environment, escalate privileges, disable security controls, and prepare follow-on actions such as data theft or ransomware.
Relevance for you
Threat actors impersonate IT support via Microsoft Teams to obtain remote access, then use PowerShell and portable Node.js runtimes to stage persistent C2 implants , an operational threat for manufacturers with remote support infrastructure.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.10
- freshness factor
- 0.60
- exploitability factor
- 1.00
- days old
- 6.00
- vendor mismatch penalty
- 0.00
Path: operational