Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringinitial-access-methodremote-access-implantcommand-and-control-method

Microsoft Teams Vishing Used to Gain Remote Access and Deploy Malware

Updated 3mo agoFirst seen Mar 18, 20263 sources

Attackers used Microsoft Teams to impersonate IT or helpdesk staff and socially engineer employees into granting access or executing malicious actions, turning collaboration tooling and trusted support workflows into the initial access vector. One report describes a compromise at an Italy-based consumer services company where a Teams meeting invite and screen sharing session led the victim to run a staged PowerShell chain that deployed PhantomBackdoor, a multi-stage WebSocket-based backdoor associated with earlier spear-phishing activity. The observed sequence included post-call PowerShell execution, device reconnaissance, and establishment of WebSocket command-and-control.

A second report describes a similar vishing intrusion in which a threat actor posing as support staff called employees through Teams and, after multiple attempts, convinced one user to grant remote access through Quick Assist. The attacker then directed the victim to a spoofed credential-harvesting site, used a malicious MSI and sideloaded DLL to launch follow-on payloads, and established outbound C2. While the malware families and exact post-compromise chains differ, both accounts document the same operational pattern: Teams-based social engineering, abuse of legitimate remote assistance or user-guided execution, credential theft or payload staging, and transition to hands-on intrusion activity inside a corporate environment.

Share:
Microsoft Teams Vishing Used to Gain Remote Access and Deploy Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 18, 20263mo ago

Cato CTRL publishes PhantomBackdoor Teams-vishing findings

Cato CTRL published research on a Teams-based vishing intrusion delivering PhantomBackdoor to an Italy-based organization. The report noted behavioral overlap with earlier SentinelOne reporting while emphasizing a different delivery method and broader concern around collaboration platforms as attack surfaces.

Microsoft publicly discloses November 2025 Teams vishing case

Microsoft publicly described the November 2025 intrusion as an example of identity-first attacks abusing trust, collaboration platforms, and legitimate Windows tools rather than software vulnerabilities. The disclosure highlighted the use of Teams and Quick Assist in the attack chain.

Microsoft DART contains and remediates the Quick Assist intrusion

Microsoft Detection and Response Team determined the compromise originated from the Teams vishing interaction, contained the incident, and found it to be short-lived and limited in scope. After remediation, Microsoft reported that no persistence mechanisms remained.

Italy-based company hit with Teams helpdesk vishing delivering PhantomBackdoor

An Italy-based consumer services company was compromised in a vishing-driven intrusion in which attackers used a Microsoft Teams helpdesk impersonation and screen-sharing interaction to get the victim to execute staged PowerShell payloads. The infection chain used fileless in-memory PowerShell, contacted maxsolutions243[.]com, and established WebSocket command-and-control for PhantomBackdoor.

Nov 1, 20258mo ago

Victim grants Quick Assist access, leading to corporate compromise

During the November 2025 campaign, a third employee was persuaded to grant remote access through Quick Assist and was then directed to a spoofed credential-harvesting site. The attacker used a disguised MSI package to sideload a malicious DLL, establish command-and-control, and deploy additional post-compromise capabilities.

Threat actor launches Teams vishing attempts against employees

In November 2025, a threat actor impersonating IT support over Microsoft Teams targeted employees in a corporate environment. Microsoft reported that two initial attempts against employees failed before the attacker reached a third user.

May 8, 20233y ago

Italy-based engineering firm targeted with Teams vishing delivering PhantomBackdoor

Cato CTRL reported a social-engineering intrusion against an Italy-based engineering firm in which attackers used voice phishing and Microsoft Teams to deliver the PhantomBackdoor malware. The case highlighted Teams as a delivery vector in a vishing-led compromise.

Vishing and Microsoft Teams Used to Deliver PhantomBackdoor - Infosec.Pub
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Malware
1 linked
Affected products
1 linked
Windows
Organizations
3 linked
Microsoft CorporationCato NetworksItaly-based engineering firm
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.