Microsoft Teams Flaw Lets Attackers Impersonate IT Helpdesk
Key Takeaways Threat actors are increasingly exploiting Microsoft Teams’ external collaboration features to conduct vishing campaigns. Attackers impersonate IT helpdesk staff to trick employees...
Key Takeaways
- Threat actors are increasingly exploiting Microsoft Teams’ external collaboration features to conduct vishing campaigns.
- Attackers impersonate IT helpdesk staff to trick employees into executing malicious commands or installing remote access tools.
- The Microsoft 365 Unified Audit Log (UAL), particularly the
CallParticipantDetailoperation, is crucial for forensic investigation and reconstructing attack timelines. - Organizations can mitigate these risks by restricting external federation, triaging suspicious external activity, and enhancing employee training.
Cybercriminals are intensifying their use of voice phishing (vishing) tactics, specifically targeting Microsoft Teams users by leveraging the platform’s external collaboration capabilities. These sophisticated attacks involve threat actors posing as internal IT support or investigators to deceive employees.
Table Of Content
The attack sequence typically begins with an unsolicited call or message initiated from an external or cross-tenant Teams account. The attacker, masquerading as a legitimate internal IT helpdesk representative, attempts to establish trust with the targeted employee.
Through social engineering, the attacker manipulates the victim into performing actions such as executing attacker-provided commands, approving remote access sessions, or installing Remote Monitoring and Management (RMM) software like Quick Assist.
A significant challenge with these attacks is their ability to bypass traditional phishing defenses. Because the interaction occurs within the seemingly secure environment of a trusted collaboration platform rather than via email, existing security measures often fail to detect the intrusion.
Microsoft’s Detection and Response Team (DART) first documented a persistent Teams voice phishing campaign in November 2025, observing this attack vector across numerous enterprise environments. Noteworthy among early adopters of this technique were affiliates of the Black Basta ransomware group, who, in 2024, weaponized Teams impersonation alongside credential theft via EvilProxy and SystemBC for persistence.
UAL as a Forensic Weapon
Security researcher Maurice Fielenbach, who is actively investigating multiple incidents involving this attack class, emphasizes the significance of the CallParticipantDetail operation within the MicrosoftTeams workload in the Unified Audit Log (UAL) as a critical forensic artifact.
This UAL event captures essential details, including participant identities, call join and leave timestamps, connection metadata, the tenant of origin, and indicators for federated or external participants. However, Fielenbach notes that the exact schema of these records can vary depending on the tenant and data ingestion path, necessitating that analysts validate field availability before implementing automated detection mechanisms.
Fielenbach also cautions against relying solely on ChatCreated events as a definitive signal from the Teams client, as its absence does not confirm that no chat interaction occurred. Furthermore, audit records typically appear within 60 to 90 minutes, without a guaranteed Service Level Agreement (SLA), and have a default retention period of 180 days.
To construct a comprehensive attack timeline, investigators must correlate CallParticipantDetail events with other relevant activities, such as MessageSent, MessageCreatedHasLink, and endpoint telemetry data. For investigations requiring access to message body content, standard UAL queries are insufficient, mandating the use of Microsoft eDiscovery and Content Search workflows.
Detection and Mitigation
Security teams are advised to implement the following defensive strategies to counter this threat:
- Restrict External Teams Federation: Limit cross-tenant communication to only those users or groups with a clearly defined business requirement.
- Triage First-Contact External Activity: Treat any unsolicited external Teams call or message, particularly if followed by URL sharing, Quick Assist launches, or script execution, as a strong indicator of potential vishing.
- Leverage UAL for Visibility: Utilize
Search-UnifiedAuditLogwith-RecordType MicrosoftTeamsand integrate with endpoint telemetry to gain a complete view of the attack kill chain. - Monitor Enrichment Signals: Where available, review
TeamsImpersonationDetectedandSecurityRiskInCallDetectedevents as additional threat indicators. - Block Unnecessary Quick Assist: Remove or disable legacy remote access tools that lack modern authentication capabilities.
- Enforce Out-of-Band Verification: Train employees to always verify IT support requests through a known, internal channel before granting any remote access.
This class of attack presents a significant challenge because it capitalizes on user trust within enterprise collaboration platforms, an attack surface that many organizations have historically under-monitored compared to email. As Teams continues to grow as a primary communication channel for hybrid workforces, the CallParticipantDetail log and other correlated UAL artifacts are becoming indispensable evidence sources in incident response. However, their effective use depends on analysts understanding their limitations and validating field schemas before integrating them into detection pipelines.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.