A wave of ransomware attacks is exploiting the trust inherent in internal communication platforms, with threat actors using Microsoft Teams to impersonate IT staff and deploy Chaos ransomware on corporate networks.
According to an analysis by BleepingComputer, the campaign targets North American organizations by initiating contact directly within Teams. Attackers pose as help-desk personnel, using voice calls and persistent chat messages to pressure employees into granting remote access. Victims are tricked into installing legitimate remote-support software like AnyDesk or executing PowerShell commands, handing over device control to the attackers.
This approach represents a key shift in the social engineering landscape. As external email filters become more effective, adversaries are moving into the trusted daily workflows of employees. By operating inside a platform like Teams, the attacks bypass the skepticism often reserved for external messages and exploit the natural assumption that internal communications are legitimate. The persistence and urgency shown in follow-up chats further erode employee defenses.
Once inside the network, the attackers follow a familiar ransomware playbook. The initial access is just the first step, leading to lateral movement, privilege escalation, and ultimately, the deployment of Chaos ransomware for financial extortion. The use of common, corporate-approved tools—a "living-off-the-land" tactic—helps the activity blend in and evade many traditional security controls.
Security researchers highlight this as a textbook case for zero-trust principles. The core vulnerability is not technical but human, stemming from automatic trust in internal sources. Organizations are urged to treat every request for access or action with verification, regardless of its apparent origin.
Effective countermeasures require a layered approach. Policy must mandate that all unsolicited remote access requests received via collaboration platforms be verified through a separate, pre-established channel, such as a ticketing system or known phone number. On the technical side, strict application allow-listing can block unauthorized software installations, while enhanced monitoring for remote-access tools and command-line activity can detect anomalous behavior. Finally, user training must evolve to specifically cover social engineering tactics targeting internal collaboration suites, teaching skepticism and verification procedures.
The observed campaign underscores that as the workplace digital ecosystem evolves, so too must its defenses. The same platforms enabling productivity can become potent attack vectors, demanding that organizations apply the same level of scrutiny to internal chat and voice channels as they do to email.
一波勒索軟件攻擊正利用內部通訊平台內建的信任機制,攻擊者利用 Microsoft Teams 假冒 IT 人員,在企業網絡中部署 Chaos 勒索軟件。
根據 BleepingComputer 的分析,此攻擊活動專門針對北美洲機構,透過 Teams 直接發起聯絡。攻擊者偽裝成 Help Desk 人員,利用語音通話及持續性的聊天訊息施壓員工,使其授予遠程存取權限。受害者被誘騙安裝 AnyDesk 等合法的遠程支援軟件,或執行 PowerShell 指令,從而將設備控制權交予攻擊者。
此手法代表社交工程領域的關鍵轉變。隨著外部電郵過濾機制日益有效,攻擊者轉而滲透員工日常使用的可信工作流程。透過在 Teams 等平台內部操作,攻擊能繞過通常針對外部訊息的懷疑態度,並利用人們對內部通訊天然認為可信的假設。後續聊天中表現出的持續性與緊急性,進一步削弱員工的防禦心理。
一旦進入網絡,攻擊者便沿用熟悉的勒索軟件攻擊模式。初始存取只是第一步,隨後進行橫向移動、權限提升,最終部署 Chaos 勒索軟件以進行財務勒索。使用常見的企業認可工具——一種「利用本地工具」的戰術——有助於攻擊活動融入環境並規避許多傳統安全控制。
安全研究人員強調,這是零信任原則的典型案例。核心漏洞並非技術層面,而是人性,源於對內部來源的自動信任。機構應對每一項存取或操作請求進行驗證,不論其表面來源為何。
有效的應對措施需採用多層次策略。政策必須規定,所有透過協作平台收到的未經主動請求的遠程存取,皆須透過獨立且預設的管道進行驗證,例如工單系統或已知電話號碼。技術方面,嚴格的軟件白名單機制可阻止未授權軟件安裝,而增強對遠程存取工具及命令行活動的監控則可偵測異常行為。最後,用戶培訓必須與時並進,專門涵蓋針對內部協作套件的社交工程戰術,教導質疑態度及驗證流程。
這次觀察到的攻擊活動突顯,隨著工作場所數字生態系統的演進,其防禦機制亦須同步提升。同樣的平台既能促進生產力,也可能成為強力的攻擊途徑,要求機構對內部聊天及語音頻道施加與電郵同等嚴格的審查標準。
