security: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Security Blog
2026-09-02
Microsoft Threat Intelligence reported a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. The campaign uses social engineering and legitimate tools to move from initial access to lateral movement, with Microsoft Defender used for detection and disruption.