09/21/2026
A coordinated vishing campaign has targeted at least 150 Microsoft Teams users across multiple companies, using trusted collaboration chats and voice calls to push remote access tools and malware.
Researchers observed the campaign between January and April across at least 10 organizations. The attackers used chat identities that mirrored internal support teams, then followed with voice calls that often lasted 10 to 15 minutes.
Two attack paths were observed.
• One relied on legitimate remote access tools such as Windows Quick Assist or third-party RMM software.
• Another aimed at organization infrastructure through files hosted in cloud infrastructure, hidden Microsoft Edge activity, and NTLM relay attempts against a domain controller.
The activity shows how trusted collaboration platforms are being used as a doorway into identity-based attacks. How should organizations adapt their security and training practices to match this shift?