
Fake IT Support Hits Teams to Drop Ransomware
Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked…
Attackers are calling employees on Microsoft Teams while pretending to be internal IT support, then persuading them to approve a Microsoft Quick Assist remote-control session. Once the employee approves, the attacker can take control of the computer and use PowerShell to install a Go-based backdoor (GoGRPC) and other tools for long-term access and data theft.
This scheme relies on a phone-style social engineering tactic delivered through Microsoft Teams rather than a traditional phone line. An attacker contacts an employee, claims to be internal IT support, and asks them to start a Microsoft Quick Assist session to resolve a supposed technical issue. Once the employee approves the session, the attacker gains live remote control of the machine. From there, PowerShell commands are used to collect device information, download additional tools, and install the GoGRPC backdoor configured to launch automatically at every sign-in. Some reported incidents may also begin with an email flood that overwhelms the target's inbox, followed by a Teams call from the fake support worker offering to fix the disruption, though this pattern has not been confirmed in every case.
The pretext works because it mirrors a routine, expected interaction. Employees are used to receiving help from IT and are conditioned to cooperate quickly when told there is a technical problem. An unsolicited Teams call from someone claiming to be internal support does not automatically look suspicious, especially if the employee is already dealing with a disrupted inbox. The request to approve a Quick Assist session feels like a normal troubleshooting step rather than a security decision, which lowers the employee's guard at the exact moment verification matters most.
Employees should treat any unexpected Teams-based IT support outreach as unverified until confirmed through a separate, known channel such as an internal phone number or support portal. No remote-control request should be approved unless the employee initiated the support ticket themselves and can confirm the identity of the person helping. Organizations that do not rely on Quick Assist for legitimate support should consider removing or blocking it from employee devices, and should also limit the ability of unknown external accounts to initiate Teams contact with staff. Building awareness around this specific pretext, a Teams call posing as internal IT, helps employees recognize the request as a decision point rather than a routine help session, reducing the chance that remote access and backdoor tools like GoGRPC are ever installed.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They contact employees over Microsoft Teams while impersonating internal IT support and persuade them to approve a Microsoft Quick Assist session, which grants remote control of the computer.
The attacker uses PowerShell commands to survey the device, download malware, and install the GoGRPC backdoor so it starts automatically whenever the user signs in.
Some incidents may begin with an email flood that fills the victim's inbox with unwanted messages, after which the fake support worker calls through Teams offering to fix it, though this is not confirmed in every case.
Companies that do not use Quick Assist should block or remove it from employee computers, and employees should verify any support request through an internal phone number, support portal, or known company contact before approving a session.
A Microsoft Teams call pops up: “IT Support here, I just need you to start Quick Assist so I can fix an issue.” Sounds normal, right? But this isn’t our helpdesk. It’s someone posing as IT, talking you into approving a Microsoft Quick Assist session. The second you click Accept, they can fully control your PC. From there, they run PowerShell, drop a GoGRPC backdoor, and quietly set up tools to steal files to cloud storage and come back later for ransomware or extortion. All from that one Quick Assist approval. If you get an unexpected Teams “IT support” call asking for Quick Assist, hang up and contact our helpdesk through the official channel you already know, don’t approve the request.

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions.…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…