There’s a devious hacking scheme that involves a hijacked Microsoft Teams account, a fake IT helpdesk, and a covert infection tool
A sophisticated social engineering campaign is targeting users through hijacked Microsoft Teams accounts that impersonate IT helpdesk services. The scheme operates in multiple variations, with some attackers using newly created Teams accounts to impersonate legitimate users, while others leverage compromised accounts from previous victims to conduct further attacks.
The attack begins when hackers establish contact with potential victims through fraudulent Teams accounts. Once initial contact is made, users are manipulated into downloading what appears to be legitimate software—a bespoke chat client or tool. This application serves as a delivery mechanism for malicious files designed to infiltrate users’ systems. The use of Microsoft Teams as an attack vector lends the scheme credibility, as users typically expect IT support to communicate through familiar workplace tools.
The recursive nature of this scam—where compromised accounts become tools for additional attacks—enables rapid expansion of the threat and creates a concerning multiplication of potential attack vectors. The scheme exploits the trust users place in IT helpdesk communications, a fundamental vulnerability in workplace security culture that makes this social engineering approach particularly effective. Users should verify IT support requests through independent channels and remain skeptical of unsolicited software downloads, regardless of their apparent source.