In recent weeks, we have observed a significant increase in targeted phishing attempts using Microsoft Teams as an entry point. The attack is simple to execute, but dangerous due to the social engineering involved.

Who hasn't received that message?

Who hasn't received a WhatsApp message from an unknown number pretending to be a relative, boss, or friend, asking for money or an urgent favor? The scam is well-known to everyone. The difference now is the setting: the application has changed.

Criminals realized that the corporate environment is a much more valuable target and took the exact same tactic into work tools. WhatsApp gave way to Microsoft Teams.

 The "uncle asking for a Pix payment" has become the "CEO asking for a file to be installed." The presentation is more sophisticated and the setting is professional, but the social engineering behind it is the same as always: exploiting trust and urgency.

And it is precisely because it seems familiar and legitimate that this new format works so well.

 

How does the scam work?

The attacker creates an external account using the name of a company executive (usually the CEO or a board member) and initiates a conversation on Teams with employees. Taking advantage of the implied authority of the name, they request urgent actions, the most common being the download and installation of files. 

These files are often disguised malware, remote access tools, or droppers that pave the way for lateral movement and credential theft.

The effectiveness of the attack lies not in technical sophistication, but in haste, fear of contradicting an authority figure, and the trust placed in a legitimate corporate platform.

warning signs

  • Pay attention when the message displays:
  • External sender (Teams displays the "External" tag or unknown domain).
  • A sense of urgency or secrecy ("I need this now," "don't tell anyone").
  • Requests to install programs, download attachments, or click on links.
  • Requests outside the normal workflow, even those coming from "executives".
  • Minor differences in display name or email address.

How to protect yourself

Be wary of any software installation requests received via chat, regardless of who appears to be sending them.

Check the sender: verify if it's marked as an external user and validate the domain.

Confirm through another channel: if the message appears to be from an executive, call or use an official channel before taking action.

Never install files without validation from the IT/Security team.

Report any suspicious approach to the SOC immediately.

 

What can be done (recommended controls)

This attack vector specifically exploits the default permissiveness of external access in Microsoft Teams. 

From a security standpoint, the attack surface needs to be reduced at the source, not just mitigated at the tip. We recommend hardening the following settings:

Restrict external access. By default, Teams allows any external domain to initiate conversations with your collaborators. Migrate from an "allow all" policy to an allowlist, allowing communication only with previously verified partner and customer domains. Anything not explicitly trusted should be blocked.

Block contacts originating from trial tenants: Trial tenant accounts are free, disposable, and a favorite playground for attackers precisely because they require no cost or robust verification. There is no legitimate business reason to receive approaches from them. Block them completely.

Block contacts from Microsoft Personal Accounts (MSA): Teams allows interaction with personal accounts (@outlook, @hotmail, @live, and similar). No legitimate corporate communication should originate from an unmanaged personal account. Disabling this channel eliminates one of the most common disguises used in this scam.

Strengthen execution and installation policies at the endpoint: Even if the message arrives, the impact only materializes when the file is executed. Application allowlisting controls, restriction of administrative privileges, and blocking the execution of binaries in user directories close the last link in the attack chain.

Keep your endpoint protection solutions up to date: Antivirus software, EDR, and other security agents only protect against what they can recognize. Outdated signatures, disabled agents, or legacy versions leave exploitable vulnerabilities even against known threats. Ensure that protection tools are active, updated, and reporting to the management console on all workstations, without exception.

Continuous monitoring and detection: Configuration is the first layer, but not the only one. Identity telemetry, alerts about new external contacts, and event correlation in the SOC provide visibility into attempts to bypass blocks. Defense in depth assumes that some control may fail and that detection needs to be prepared for that.

The logic is the same as any surface area reduction strategy: Every permission granted is a door. If it doesn't serve a clear business purpose, it serves an attacker.

When in doubt, don't click, don't install, and report it.

Safety is everyone's responsibility.

 

Count on Ayko to strengthen the security of your Microsoft environment. 

Impersonation attacks are becoming increasingly sophisticated and exploit user trust to compromise critical data, access, and operations. Therefore, protecting Microsoft requires a strategy that combines monitoring, identity security, endpoint protection, backup, and data recovery.

With 22 years of experience in information security, infrastructure, and business continuity, Ayko helps companies reduce risks, increase digital resilience, and ensure the protection of their corporate environments.

Speak with an Ayko specialist and discover how to strengthen your Microsoft security against the latest threats.