The Rise of “Teams Vishing”: How Attackers Are Exploiting Trust in the Age of Collaboration
Cybersecurity threats are constantly evolving, but a particularly insidious trend is gaining momentum: “Teams vishing.” This isn’t about breaking into systems; it’s about manipulating people. Attackers are increasingly leveraging Microsoft Teams, a platform built on trust and collaboration, to infiltrate organizations with alarming speed and efficiency. The CyOps threat operations unit has observed a significant rise in this activity, turning everyday communication into a potential security breach.
From Phishing Emails to Urgent Phone Calls – On Teams
For years, phishing emails have been the go-to method for social engineering attacks. Now, attackers are bypassing the need for users to click suspicious links. Instead, they’re directly calling employees within Teams, posing as trusted figures – most often IT support staff. This shift represents a fundamental change in tactics, exploiting the inherent trust users place in internal communications.
In a recent 2025 incident, an attacker contacted a manufacturing employee via Teams, impersonating IT support. The employee granted remote access using QuickAssist, a legitimate Microsoft tool. Within minutes, the attacker had established persistent control, mapping the environment and preparing for further malicious activity. This highlights a dangerous trend: attackers are abusing trusted platforms and tools to remain undetected – a tactic dubbed “identity-bending.”
How Does a Teams Vishing Attack Unfold?
The attack typically follows a multi-stage process:
Email Bombing: Lowering Defenses
Some attackers begin by “email bombing” targeted users, subscribing them to numerous legitimate sites and services. This floods the user’s inbox with registration and password reset emails, creating a sense of normalcy that allows the attacker to contact the user directly with a perceived legitimate reason.
Teams Vishing: The Impersonation Game
The attacker initiates contact via Teams, often from an external domain, using a display name designed to mimic the IT or Helpdesk department (e.g., “IT Support,” “Helpdesk”). They then attempt to convince the user to grant remote access to their machine under the guise of resolving a technical issue.
Attackers are even leveraging legitimate Microsoft domains ending in “*.onmicrosoft.com” to appear more authentic, capitalizing on the trust associated with the Microsoft brand.
Examples of attacker display names include: “IT Support🛡️ | Corporate IT Service 🛠️ (Internal).”
Common attacker domains observed include: corporate@ITElectronicsHelpDesk[.]onmicrosoft[.]com, Services@HelpDeskEngineeringIT[.]onmicrosoft[.]com, and ithelpdesk@DailyExternalSystem[.]onmicrosoft[.]com.
RMM: Gaining Control
Once access is granted, attackers utilize Remote Monitoring and Management (RMM) tools like QuickAssist and Anydesk to establish a foothold. QuickAssist is particularly favored as it’s built into Windows, avoiding the need for users to download additional applications and potentially raise suspicion.
Execution of Malicious Code: The Payload
With control established, attackers deploy and execute malicious files, often installing backdoors for persistent access. Techniques like DLL sideloading and DLL proxying are frequently employed.
The speed of these attacks is alarming. Data shows that attackers can compromise a host in as little as 3 minutes from the start of the conversation, targeting as few as 2 users before achieving success.
Why This Matters to MSPs
The simplicity and effectiveness of Teams vishing pose a significant threat to Managed Service Providers (MSPs). The attack weaponizes the trusted relationship MSPs build with their clients. If a client’s employee is conditioned to follow instructions from “IT,” they become a vulnerable point. A single successful session can lead to ransomware deployment or lateral movement across a client’s network, resulting in financial loss, legal liability, and reputational damage.
Protecting Your Organization: Best Practices
Mitigating the risk of Teams vishing requires a multi-layered approach:
- Review Microsoft Teams external access settings: Many organizations have external contact enabled by default. Consider requiring approval before external parties can initiate contact.
- Expand security awareness training: Training should extend beyond email phishing to include social engineering tactics used on collaboration platforms, incorporating realistic voice and video call simulations.
- Monitor end-user deployment of remote access tools: Even legitimate tools like QuickAssist should trigger alerts and require validation before proceeding.
Future Trends: AI and the Evolution of Social Engineering
The CyOps ECHO Report highlights a concerning trend: the increasing use of Artificial Intelligence (AI) to amplify social engineering attacks. More than 40% of vulnerabilities added to the CISA KEV in 2025 were zero-days, and attackers are leveraging AI to operationalize these flaws within hours of disclosure.
Specifically, AI is being used to:
- Create hyper-realistic phishing campaigns: AI-powered campaigns dynamically personalize themselves, making them more convincing.
- Accelerate malware development: AI enables attackers to build and modify malware faster, even for less skilled criminals.
This suggests that Teams vishing attacks will become even more sophisticated and difficult to detect, requiring organizations to invest in advanced threat detection and response capabilities.
FAQ
Q: What is Teams vishing?
A: Teams vishing is a social engineering attack where attackers use Microsoft Teams to impersonate trusted individuals, typically IT support, to gain remote access to a user’s device.
Q: How can I protect my organization from Teams vishing?
A: Review Teams external access settings, expand security awareness training, and monitor the use of remote access tools.
Q: Is QuickAssist a security risk?
A: While QuickAssist is a legitimate tool, attackers are exploiting it to gain unauthorized access. Monitoring its use and requiring validation is crucial.
Q: What role does AI play in these attacks?
A: AI is being used to create more convincing phishing campaigns and accelerate malware development, making attacks more sophisticated.
Did you know? Attackers can compromise a system in as little as 3 minutes using Teams vishing tactics.
Stay informed about the latest threats and best practices. Explore our other articles on cybersecurity awareness and threat intelligence to bolster your defenses.
Related reading