Attackers Phish via Teams & Slack, Not Email

Unit 42 · High sophistication
Last updated August 20, 2026

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through authenticated, familiar channels, they can look routine and bypass traditional email-focused defenses.

Key findings

  • Attackers increasingly misuse collaboration platforms (Teams/Slack) for identity phishing, impersonation, credential theft, and malware delivery.
  • Unit 42 reports collaboration-tool malicious alerts “more than quadrupled” over 12 months and that “99% of the alerts generated related to chat phishing operations.”
  • Attackers exploit external federation/guest access/trusted relationships to reach victims through authenticated channels that look normal.
  • Real incidents include malware delivered via a RAR sent in a Teams chat and credential theft via Slack DMs that led to a fake Google Workspace login and certificate installation.
  • Post-compromise persistence/exfiltration can be done via legitimate integrations, such as a Slack webhook used to send stolen privileged credentials.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk / IT support, Engineering / Developers, Open source maintainers, Security operations (SOC).
  • Affected industries: Technology, Software supply chain / open source, Manufacturing, Any organization using SaaS collaboration tools (Teams/Slack).
  • Attack channels: teams, slack, website.
  • Impersonated: Internal IT support (or trusted personnel), A known coworker/contact using a compromised account, Known Linux Foundation community leader.

Awareness takeaways

  • Treat Teams/Slack messages as potential phishing, even if they come from an authenticated platform or familiar workspace.
  • Be suspicious of chat-based requests to click links, approve MFA prompts, install remote access tools, or share credentials.
  • Do not open unexpected archives or executables received via chat; report them to security.
  • Never install certificates or run downloaded binaries as part of an ‘authentication’ or ‘verification’ process.

Red flags to watch for

  • Unexpected IT outreach via chat from an unfamiliar or external account
  • Pressure to click a link or approve an MFA prompt you didn’t initiate
  • Conversation initiated via external federation/guest context
  • Unexpected archive file (.rar) received over chat
  • Instruction to open/run content from Downloads
  • File extracts a DLL (not a normal business document)
  • Login request delivered via Slack DM with an external web link
  • Site requests a “verification code” and then asks to install a root certificate
  • Unexpected download/execution prompts during “authentication”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in Teams, a chat pops up: “Hi, this is IT support, we need you to verify your account.” Looks normal, right? Attackers are skipping email and living in Teams and Slack now. Unit 42 saw chat-based phishing alerts more than quadruple, and 99% were phishing ops. The playbook: they DM you as IT or a coworker, send a link to a fake login, push you to approve an MFA prompt, or drop a RAR file that quietly unpacks malware. Aha moment: if a chat asks you to click a login link, approve MFA you didn’t start, or open an unexpected file, pause and report it to security instead of responding.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026