// Alert

Microsoft 365 threat report

Microsoft Threat Intelligence disclosed an active human-operated intrusion campaign exploiting Microsoft Teams external collaboration to impersonate IT support and socially engineer remote access. Attackers deploy a Node.js-based JavaScript implant enabling persistent command execution, then conduct Active Directory reconnaissance and lateral movement via WinRM toward domain controllers. The campaign uses legitimate tools to evade detection and can precede ransomware deployment or data theft.

// Get alerts for Microsoft 365