Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.
Indicators of Compromise
- hash: 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d
- hash: a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676
- hash: cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5
- hash: 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3
- hash: 69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23
- hash: a135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87
- domain: dssdfvsdfvsdfvsdgbfbdvdzv.org
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Description
Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/"]
- Adversary
- null
- Pulse Id
- 6a98ece13ef339971e686ab5
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d | — | |
hasha4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 | — | |
hashcc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 | — | |
hash0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 | — | |
hash69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23 | — | |
hasha135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaindssdfvsdfvsdfvsdgbfbdvdzv.org | — |
Threat ID: 6a992751acd9273b49a066f0
Added to database: 09/03/2026, 07:52:49 UTC
Last updated: 09/03/2026, 14:40:32 UTC
Views: 34
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.