Skip to content
Auto-CTI
Back to today
NEW HIGH B3

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

B Microsoft Security Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Threat actors impersonate IT support via Microsoft Teams to obtain remote access, then use PowerShell and portable Node.js runtimes to stage persistent C2 implants , an operational threat for manufacturers with remote support infrastructure.

Description

An actively conducted intrusion campaign abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel, socially engineering users into granting interactive remote access. After establishing remote control via RMM tools, attackers use PowerShell to download and silently install a malicious MSI package that stages a portable Node.js runtime and an obfuscated JavaScript implant. The implant provides persistent command execution and C2 communication, followed by manual hands-on-keyboard lateral movement and data collection. The campaign employs defense-evasion techniques including masquerading (helpdesk/update-themed MSI names) and process injection via Rundll32.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
0.60
exploitability factor
1.00
days old
6.00
vendor mismatch penalty
0.00

Path: operational

ESC