Microsoft Threat Intelligence
Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel & abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution & C2. https://msft.it/6010apXAw After establishing access, the attackers use trusted tooling to perform reconnaissance, capture screenshots, execute follow-on payloads, and move laterally toward domain controllers, certificate authorities, and other high-value systems. Organizations should restrict Teams external access to trusted domains, reinforce user education, and harden systems against social engineering. Read the blog for analysis, Microsoft Defender coverage, indicators, hunting queries, and mitigation guidance.