Generalmicrosoft.com·8d ago

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Submitted by @
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft S

ORIGINAL REPORTING
Microsoft Security
Published 8d ago ago · Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari
Read announcement at Microsoft Security

Original reporting by Microsoft Security · Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari. GridIndex is an aggregation and intelligence layer — full credit to the original publisher.

CONTINUE READING

This page summarizes and tracks coverage of this developing story.

Read announcement at Microsoft Security
0 views 0 upvotes 0 comments 0 shares

Discussion · 0

Sign in to join the discussion.