Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-02 and was added to the RWP archive on 2026-09-07.
Fake IT on Teams was not vishing-for-a-stealer — it was hands-on-keyboard to the domain controller
External-tenant Teams chat impersonating helpdesk, Quick Assist / request-control, silent MSI, portable Node.js implant, then WinRM toward DCs.
Bottom line up front
CONFIRMED 2 September 2026 Microsoft — human-operated campaign using Teams external collaboration to impersonate IT/helpdesk. User grants interactive remote (Teams request-control or Quick Assist code). PowerShell pulls a silent MSI; portable Node.js + obfuscated JS implant for persistent C2. Then AD recon, screenshots, LOLBins, WinRM toward high-value assets including domain controllers. Not commodity infostealer-and-leave. Related in method to 2025 Teams-as-attack-surface (already in this archive) and Unit 42 Spring Ring vishing; not merged — this is the 2026 hands-on-keyboard write-up.
Historical backfill of 2 September 2026 reporting; added 7 September 2026.
What happened
The helpdesk channel became the initial-access broker. External tenant + "I need to take control" is the whole exploit.
Why it mattered
Conditional access that ignores Teams remote-control and Quick Assist will watch a DC get WinRM'd by a Node implant that looked like IT.
Who / what was affected
Microsoft-observed enterprises using Teams external access. Counts UNKNOWN.
Technical context
Disable external Teams where not required. Alert on Quick Assist / unexpected MSI from user context. Hunt portable node.exe + WinRM from workstations.
Exploitation / threat status at the time
CONFIRMED Microsoft campaign chain.
UNKNOWN actor name.
What defenders should have done
- External access = off or tightly allow-listed.
- Users do not read back Quick Assist codes to chat strangers.
- Assume domain recon after any unsolicited remote session.
RWP assessment
Confidence: High. Identity and collaboration are one control plane.
Defensive actions
- Block Quick Assist for standard users.
- EDR on Node in user-writable paths.
- Tabletop: fake helpdesk on Teams to DC.
Sources
- Microsoft Threat Intelligence — Impersonating IT support
- Microsoft — Disrupting threats targeting Microsoft Teams
- Unit 42 — Spring Ring voice phishing in Microsoft Teams