Your Next Teams Call from IT Support Might Not Be Real

Attackers are calling employees on Microsoft Teams, pretending to be IT support, and convincing them to install remote access tools. The same tactic just cost an Am Law 100 firm 57,000 exposed records.

A few weeks ago, Palo Alto Networks documented a campaign where attackers called employees on Microsoft Teams, pretending to be IT support. The calls came from external accounts with names like “System Administrator” and “helpdesk@Progressive936.” Teams displayed an “External unfamiliar” label on the call, but most people don’t know what that means or think to look for it.

The attack started with a phishing email disguised as an employee survey. Shortly after someone opened the PDF, they got a Teams voice call from “IT support” asking them to share their screen so the tech could “help resolve an issue.” The attacker then walked them through installing legitimate remote access tools like AnyDesk and HopToDesk. Once those were running, they downloaded malware onto the machine.

From there, the attacker had full access: execute commands, steal files, maintain persistence. The malware (called EtherRAT) uses Ethereum blockchain contracts to find its command servers, which makes it harder to shut down.

And this isn’t a one-off. In a separate campaign the same week, Blank Rome, an Am Law 100 firm, disclosed that a cybercriminal posing as the firm’s IT department convinced an attorney to upload files to an external website. That breach exposed personal information for more than 57,000 people, including Social Security numbers. Two class action suits followed.

We covered a version of this pattern earlier with callback phishing, where attackers called law firm employees pretending to resolve a billing issue. The channel has changed from phone calls to Teams calls, but the playbook is the same.

Why this works

The attack exploits something simple: employees trust their IT department. When someone calls from “IT support” and says they need to fix something on your computer, most people comply. It’s what you’d normally do.

Microsoft Teams makes this easier for attackers because external users can call into an organization’s Teams environment. The call looks like any other Teams call. The “External” label is small and easy to miss, especially on a phone.

The attackers are also pairing the call with a phishing email sent just before. So when “IT” calls about a problem right after you opened a suspicious attachment, the timing feels like a legitimate response.

What Microsoft is doing about it

Microsoft has been adding protections in response to the growing number of Teams-based attacks:

  • External caller warnings now display more prominently in Teams, flagging calls from outside your organization.
  • A new administrator policy automatically places suspected third-party bots into the meeting lobby until someone manually approves them.
  • Brand impersonation warnings can identify when callers are spoofing known company names.

But these protections need to be configured. They’re not all on by default, and most small businesses haven’t turned them on because they don’t know the settings exist.

Questions to ask your IT provider

“Are external Teams calls and chats restricted or flagged in our environment?” Your IT provider can configure Teams to block external voice calls entirely, or at minimum ensure that external caller warnings are clearly displayed. Most small firm deployments leave external access wide open because it was easier during setup.

“If someone called our staff pretending to be IT support, would our team know how to verify the call?” This isn’t a technology question. It’s a training question. Your staff should know that legitimate IT support will never ask them to install software from an unfamiliar source during an unscheduled call. They should know how to verify by calling back on a known number.

“Do we allow remote access tool installation on workstations?” Tools like AnyDesk, HopToDesk, and TeamViewer are legitimate, but they’re also the tools attackers use most often. Application control policies can prevent users from installing them without IT approval. If your firm doesn’t restrict this, anyone who falls for the call can hand over full access to the machine.

“When was the last time we reviewed our Teams security settings?” Microsoft has been rolling out new protections for months. If your Teams environment was configured two years ago and nobody has revisited the security settings since, you’re missing protections that exist specifically because of attacks like this one.

The pattern to recognize

This attack follows a formula that’s becoming common: create a small moment of worry (a suspicious email), then offer to fix it (the “IT support” call). The combination of anxiety and helpfulness bypasses the skepticism people would normally have.

Your staff doesn’t need to become security experts. They need one rule: if someone contacts you asking to install software or share your screen, verify who they are through a separate channel before doing anything. Call the IT help desk number you already know. Send a message in a channel you trust. If it’s really IT support, they’ll understand the caution.


Artech Solutions configures and manages Microsoft Teams security for law firms and professional services firms across the Des Moines metro. If your firm hasn’t reviewed its Teams external access settings recently, we can walk through what needs to change.