Historical intelligence backfill. This assessment covers reporting originally published on 2025-10-07 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

Microsoft Teams is an authentication and remote-support channel that attackers already treat as one

Microsoft's 7 October 2025 hardening guide frames Teams as a full attack path — lures, token theft, malware delivery, and trusted-calling — not a chat add-on.

RWP Ventures · 2026-09-07 · event 2025-10-07 · 3 min read · priority 7.6

Bottom line up front

CONFIRMED On 7 October 2025 Microsoft Threat Intelligence published a long-form guide on how criminal and state actors abuse Teams across the intrusion chain: external chat, meeting lures, device-code phishing, malware in messages and calls, spoofed installers, and persistence that looks like collaboration. Named examples in that period include Storm-2372 using Teams-themed device-code flows to steal tokens, and Storm-0324 using TeamsPhisher-style lures toward JSSloader for Sangria Tempest. Secondary reporting the same week matches the "Teams is now a primary channel" framing.

This is not a Teams CVE. It is a trust-surface problem. Historical backfill of 7 October 2025 reporting; added 7 September 2026.

What happened

Microsoft walked the attack chain on its own product because the product is where work happens. The interesting cases:

A later October 2025 UC Today piece described Microsoft revoking 200+ certificates around Vanilla Tempest / Oyster / Rhysida fake Teams installers. That is a related installer-trust problem, not the same blog, and we treat it as corroboration that Teams branding is a delivery lure.

Why it mattered

Email teams spent a decade on SPF/DKIM/DMARC. Collaboration tenants often still allow:

Once the victim is in a call, screen share and Quick Assist-class remote support finish the job. That is identity plus endpoint, not "user clicked a GIF."

Who / what was affected

Any Entra tenant with Teams enabled and default-ish external access. Microsoft did not publish a single victim vertical. Finance, help desks, and executives are the practical targeting set because they answer calls.

OT impact: UNKNOWN / not claimed. A plant that uses Teams for shift handover has an IT identity problem that can become an engineering-workstation problem if those accounts are the same.

Technical context

Hardening Microsoft actually pointed at, without turning this into a product pitch:

Exploitation / threat status at the time

CONFIRMED multiple named actors using Teams as lure or C2-adjacent chat.

REPORTED fake installer and certificate-abuse campaigns using Teams branding.

ASSESSED (high): default-open external chat is sufficient for many intrusions; no zero-day required.

What defenders should have done

  1. External access review: who can start a chat with a user who has never heard of them.
  2. Disable device-code flow unless a kiosk/legacy case is documented; alert on it everywhere else.
  3. Help-desk protocol: no password or MFA reset from an inbound Teams call. Call back on a known number.
  4. Block unknown Teams installers; only Intune/Company Portal.
  5. Log Teams message attachments and meeting-created accounts the way you log email.

What we know now

2026 Unit 42 "Spring Ring" vishing in Teams (later registry item) is the same movie with a seasonal title. The control set did not change.

RWP assessment

Confidence: High that Teams is a first-class initial-access channel as of October 2025. The remaining argument is governance, not detection science.

Defensive actions

  1. Tenant external-access baseline this week.
  2. Kill device-code where unused.
  3. Train help desk on inbound Teams vish; measure with a tabletop, not a poster.
  4. Certificate and installer allow-listing for the Teams client itself.

Sources

  1. Microsoft Threat Intelligence — Disrupting threats targeting Microsoft Teams
  2. Cybernews — Microsoft warns about hackers abusing Teams
  3. UC Today — Microsoft revokes 200 fraudulent certificates targeting Teams