Hackers are abusing Microsoft Teams chats to impersonate IT help desk staff, trick employees into installing malware or granting remote access, and steal Windows passwords through a fake lock screen. The attacks don’t require a software vulnerability they rely on an employee trusting a convincing message from what appears to be internal IT support. Attackers start the campaign from Microsoft 365 tenants they control. They create display names such as “IT Service Desk” or “Help Desk,” then contact employees through Teams external chat. Because Teams allows communication with external domains by default, attackers can reach users from another Microsoft 365 tenant if external access is enabled on both sides. The...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!