Threat actors impersonated internal IT over Microsoft Teams and convinced users to start Quick Assist remote sessions. Once connected they harvested credentials via spoofed web forms and deployed MSI packages that sideloaded malicious DLLs to establish command-and-control and persistent access. The campaign exploits permissive Teams external messaging and user trust in collaboration tools.
Part of the PlainSec briefing for 2026-03-17