Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-07 and was added to the RWP archive on 2026-09-07.
Microsoft Teams is an authentication and remote-support channel that attackers already treat as one
Microsoft's 7 October 2025 hardening guide frames Teams as a full attack path — lures, token theft, malware delivery, and trusted-calling — not a chat add-on.
Bottom line up front
CONFIRMED On 7 October 2025 Microsoft Threat Intelligence published a long-form guide on how criminal and state actors abuse Teams across the intrusion chain: external chat, meeting lures, device-code phishing, malware in messages and calls, spoofed installers, and persistence that looks like collaboration. Named examples in that period include Storm-2372 using Teams-themed device-code flows to steal tokens, and Storm-0324 using TeamsPhisher-style lures toward JSSloader for Sangria Tempest. Secondary reporting the same week matches the "Teams is now a primary channel" framing.
This is not a Teams CVE. It is a trust-surface problem. Historical backfill of 7 October 2025 reporting; added 7 September 2026.
What happened
Microsoft walked the attack chain on its own product because the product is where work happens. The interesting cases:
- Device-code and meeting-invite social engineering (Storm-2372): chat builds rapport, then the victim types a code the actor generated. Token theft, not password guessing.
- Teams as malware transport (Storm-0324 / Sangria Tempest): internal-looking messages beat email filters that still treat Teams as "safe."
- Malvertising and fake Teams-for-Mac installers (Malwarebytes, cited by Microsoft, July 2025): users searching for a client.
- Email-bomb plus fake support (Storm-1811 pattern Microsoft recalls): the same help-desk vish, now with a Teams call button.
- Midnight Blizzard-style tech-support impersonation using authentication-code theater.
A later October 2025 UC Today piece described Microsoft revoking 200+ certificates around Vanilla Tempest / Oyster / Rhysida fake Teams installers. That is a related installer-trust problem, not the same blog, and we treat it as corroboration that Teams branding is a delivery lure.
Why it mattered
Email teams spent a decade on SPF/DKIM/DMARC. Collaboration tenants often still allow:
- external users to chat anyone
- unmanaged devices in meetings
- application permissions that would never pass an OAuth review if they were "just another SaaS"
Once the victim is in a call, screen share and Quick Assist-class remote support finish the job. That is identity plus endpoint, not "user clicked a GIF."
Who / what was affected
Any Entra tenant with Teams enabled and default-ish external access. Microsoft did not publish a single victim vertical. Finance, help desks, and executives are the practical targeting set because they answer calls.
OT impact: UNKNOWN / not claimed. A plant that uses Teams for shift handover has an IT identity problem that can become an engineering-workstation problem if those accounts are the same.
Technical context
Hardening Microsoft actually pointed at, without turning this into a product pitch:
- Restrict external access and guest defaults; do not let anonymous meeting join be the path to a company user.
- Disable or tightly control application installation and sideloaded apps.
- Prefer phishing-resistant MFA; disable or alert on device-code flow where the business does not need it.
- Endpoint: block consumer remote-support tools; require that IT remote support use a named, logged product.
- Safe-links / attachment scanning on Teams, not only Exchange.
Exploitation / threat status at the time
CONFIRMED multiple named actors using Teams as lure or C2-adjacent chat.
REPORTED fake installer and certificate-abuse campaigns using Teams branding.
ASSESSED (high): default-open external chat is sufficient for many intrusions; no zero-day required.
What defenders should have done
- External access review: who can start a chat with a user who has never heard of them.
- Disable device-code flow unless a kiosk/legacy case is documented; alert on it everywhere else.
- Help-desk protocol: no password or MFA reset from an inbound Teams call. Call back on a known number.
- Block unknown Teams installers; only Intune/Company Portal.
- Log Teams message attachments and meeting-created accounts the way you log email.
What we know now
2026 Unit 42 "Spring Ring" vishing in Teams (later registry item) is the same movie with a seasonal title. The control set did not change.
RWP assessment
Confidence: High that Teams is a first-class initial-access channel as of October 2025. The remaining argument is governance, not detection science.
Defensive actions
- Tenant external-access baseline this week.
- Kill device-code where unused.
- Train help desk on inbound Teams vish; measure with a tabletop, not a poster.
- Certificate and installer allow-listing for the Teams client itself.
Sources
- Microsoft Threat Intelligence — Disrupting threats targeting Microsoft Teams
- Cybernews — Microsoft warns about hackers abusing Teams
- UC Today — Microsoft revokes 200 fraudulent certificates targeting Teams