Cyber Security News

Hackers Exploit Teams’ Functionality to Steal Credentials Mimicking Microsoft Services

A sophisticated phishing campaign has been identified in which threat actors are abusing legitimate Microsoft Teams functionality to distribute malicious content that appears to originate from trusted Microsoft services.

By leveraging the platform’s “Invite a Guest” feature and crafting deceptive team names, attackers are bypassing traditional email security controls to deliver fraudulent billing notifications directly to victims’ inboxes.

The attack methodology relies on exploiting the trust users place in automated notifications from collaboration platforms. Rather than spoofing email addresses or injecting malicious URLs, the attackers create new teams within Microsoft Teams, assigning them names designed to mimic urgent financial alerts. These names often reference subscription renewals or auto-pay notices to induce panic.

A specific example observed in the wild includes team names such as: “Subscription Auto-Pay Notice (Ivoice ID: 2025_614632PPOT_SAG Amount 629. 98 USD). If you did not authorize or complete this m0nthly Payment,plese c0ntact our support team urgently.”

Once the team is created, the attacker sends invitations to external targets using the native “Invite a Guest” feature. The recipient receives an email directly from a legitimate Microsoft address (e.g., noreply@email.teams.microsoft.com).

Fake Microsoft Teams Invite (Source: Checkpoint)

Because the email infrastructure is genuine, it easily passes SPF, DKIM, and DMARC checks. However, the body of the email displays the malicious team name containing the fraudulent billing message and a support phone number in a large, prominent font.

This campaign is distinct in its use of phone-based social engineering (vishing). Instead of directing users to a credential-harvesting site, the text instructs victims to call a fraudulent support line to resolve the alleged charge.

To evade automated content filters, attackers employ obfuscation techniques within the team name, utilizing character substitutions, mixed Unicode characters, and visually similar glyphs.

The scale of this operation is significant, with telemetry indicating a broad, indiscriminate approach rather than targeted espionage. Security researchers recorded a total of 12,866 phishing messages distributed during the campaign’s peak, averaging 990 messages daily. These attacks reached approximately 6,135 distinct customers.

The distribution of targets suggests the attackers aimed to exploit widespread Microsoft Teams adoption. The manufacturing, engineering, and construction sectors bore the brunt of the activity, accounting for 27.4% of affected organizations.

This was followed by the Technology/SaaS/IT sector at 18.6% and the Education sector at 14.9%. Other affected verticals included professional services, government, and finance.

Geographic Distribution of Targets

The campaign demonstrated a global reach, though the primary focus remained on North American targets. Organizations in the United States comprised 67.9% of the victim pool. European entities accounted for 15.8%, followed by Asia at 6.4%.

A specific regional breakdown of the Latin American (LATAM) impact shows a concentration in Brazil and Mexico:

CountryPercentage of LATAM Targets
Brazil44%
Mexico31%
Argentina11%
Colombia8%
Chile4%
Peru2%

This campaign highlights a critical gap in collaboration security: the reliance on content inspection within invitations generated by trusted platforms. Since the email delivery mechanism is legitimate, organizations cannot rely solely on email authentication protocols to block these threats.

Security teams are advised to educate users on scrutinizing unexpected Teams invitations, particularly those containing urgent financial language, phone numbers, or unusual character formatting.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago