Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-02 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

Fake IT on Teams was not vishing-for-a-stealer — it was hands-on-keyboard to the domain controller

External-tenant Teams chat impersonating helpdesk, Quick Assist / request-control, silent MSI, portable Node.js implant, then WinRM toward DCs.

RWP Ventures · 2026-09-07 · event 2026-09-02 · 1 min read · priority 8.6

Bottom line up front

CONFIRMED 2 September 2026 Microsoft — human-operated campaign using Teams external collaboration to impersonate IT/helpdesk. User grants interactive remote (Teams request-control or Quick Assist code). PowerShell pulls a silent MSI; portable Node.js + obfuscated JS implant for persistent C2. Then AD recon, screenshots, LOLBins, WinRM toward high-value assets including domain controllers. Not commodity infostealer-and-leave. Related in method to 2025 Teams-as-attack-surface (already in this archive) and Unit 42 Spring Ring vishing; not merged — this is the 2026 hands-on-keyboard write-up.

Historical backfill of 2 September 2026 reporting; added 7 September 2026.

What happened

The helpdesk channel became the initial-access broker. External tenant + "I need to take control" is the whole exploit.

Why it mattered

Conditional access that ignores Teams remote-control and Quick Assist will watch a DC get WinRM'd by a Node implant that looked like IT.

Who / what was affected

Microsoft-observed enterprises using Teams external access. Counts UNKNOWN.

Technical context

Disable external Teams where not required. Alert on Quick Assist / unexpected MSI from user context. Hunt portable node.exe + WinRM from workstations.

Exploitation / threat status at the time

CONFIRMED Microsoft campaign chain.

UNKNOWN actor name.

What defenders should have done

  1. External access = off or tightly allow-listed.
  2. Users do not read back Quick Assist codes to chat strangers.
  3. Assume domain recon after any unsolicited remote session.

RWP assessment

Confidence: High. Identity and collaboration are one control plane.

Defensive actions

  1. Block Quick Assist for standard users.
  2. EDR on Node in user-writable paths.
  3. Tabletop: fake helpdesk on Teams to DC.

Sources

  1. Microsoft Threat Intelligence — Impersonating IT support
  2. Microsoft — Disrupting threats targeting Microsoft Teams
  3. Unit 42 — Spring Ring voice phishing in Microsoft Teams