Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

0
Medium
Published: 09/03/2026 (09/03/2026, 03:43:29 UTC)
Source: AlienVault OTX General

Description

Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/"]
Adversary
null
Pulse Id
6a98ece13ef339971e686ab5
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d
hasha4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676
hashcc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5
hash0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3
hash69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23
hasha135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87

Domain

ValueDescriptionCopy
domaindssdfvsdfvsdfvsdgbfbdvdzv.org

Threat ID: 6a992751acd9273b49a066f0

Added to database: 09/03/2026, 07:52:49 UTC

Last updated: 09/03/2026, 14:40:32 UTC

Views: 34

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses