Attackers Phish via Teams & Slack, Not Email

Unit 42 · High sophistication
Last updated August 20, 2026

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through authenticated, familiar channels, they can look routine and bypass traditional email-focused defenses.

Key findings

  • Attackers increasingly misuse collaboration platforms (Teams/Slack) for identity phishing, impersonation, credential theft, and malware delivery.
  • Unit 42 reports collaboration-tool malicious alerts “more than quadrupled” over 12 months and that “99% of the alerts generated related to chat phishing operations.”
  • Attackers exploit external federation/guest access/trusted relationships to reach victims through authenticated channels that look normal.
  • Real incidents include malware delivered via a RAR sent in a Teams chat and credential theft via Slack DMs that led to a fake Google Workspace login and certificate installation.
  • Post-compromise persistence/exfiltration can be done via legitimate integrations, such as a Slack webhook used to send stolen privileged credentials.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk / IT support, Engineering / Developers, Open source maintainers, Security operations (SOC).
  • Affected industries: Technology, Software supply chain / open source, Manufacturing, Any organization using SaaS collaboration tools (Teams/Slack).
  • Attack channels: teams, slack, website.
  • Impersonated: Internal IT support (or trusted personnel), A known coworker/contact using a compromised account, Known Linux Foundation community leader.

Awareness takeaways

  • Treat Teams/Slack messages as potential phishing, even if they come from an authenticated platform or familiar workspace.
  • Be suspicious of chat-based requests to click links, approve MFA prompts, install remote access tools, or share credentials.
  • Do not open unexpected archives or executables received via chat; report them to security.
  • Never install certificates or run downloaded binaries as part of an ‘authentication’ or ‘verification’ process.

Red flags to watch for

  • Unexpected IT outreach via chat from an unfamiliar or external account
  • Pressure to click a link or approve an MFA prompt you didn’t initiate
  • Conversation initiated via external federation/guest context
  • Unexpected archive file (.rar) received over chat
  • Instruction to open/run content from Downloads
  • File extracts a DLL (not a normal business document)
  • Login request delivered via Slack DM with an external web link
  • Site requests a “verification code” and then asks to install a root certificate
  • Unexpected download/execution prompts during “authentication”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in Teams, a chat pops up: “Hi, this is IT support, we need you to verify your account.” Looks normal, right? Attackers are skipping email and living in Teams and Slack now. Unit 42 saw chat-based phishing alerts more than quadruple, and 99% were phishing ops. The playbook: they DM you as IT or a coworker, send a link to a fake login, push you to approve an MFA prompt, or drop a RAR file that quietly unpacks malware. Aha moment: if a chat asks you to click a login link, approve MFA you didn’t start, or open an unexpected file, pause and report it to security instead of responding.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026