Microsoft Teams Hijinks: Fake Tech Support Scams Targeting Your Inbox!

Microsoft Teams is the unexpected star in a cyber thriller, as two hacking groups exploit its default settings to drop malware and wreak havoc. Sophos warns that STAC5143 and STAC5777 are impersonating IT support in Microsoft 365 tenants, turning innocent Teams chats into a high-stakes game of malware deployment and data theft.

Pro Dashboard

Hot Take:

Looks like Microsoft Teams has a new team member: the cyber-criminal! Who knew that posing as tech support could be the latest trend in the hacker’s handbook? Maybe it’s time we all started questioning those unsolicited “Help Desk Manager” calls. Next thing you know, we’ll be getting phishing emails from our imaginary friends!

Key Points:

  • Two threat groups, STAC5143 and STAC5777, are exploiting Microsoft 365 and Teams configurations.
  • Both groups use spam messages and fake tech support personas to gain remote access.
  • STAC5143 uses PowerShell commands and Python payloads for backdoor installations.
  • STAC5777 relies on “hands-on-keyboard” tactics and lateral movement within networks.
  • Sophos advises organizations to raise awareness about these social engineering tactics.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?