A sophisticated cybersecurity threat has emerged targeting Microsoft Teams users through an elaborate social engineering campaign that deploys the dangerous DarkGate malware. Security researchers have identified a complex attack pattern where cybercriminals are exploiting Teams’ voice call features to compromise corporate systems.
DarkGate attack methodology

The attack begins with threat actors flooding potential victims’ inboxes with thousands of emails. Following this initial bombardment, attackers initiate Microsoft Teams calls, posing as employees from external suppliers. During these calls, the attackers attempt a two-pronged approach:
- First attempting to install a Microsoft Remote Support application.
- When that fails, convincing users to download and install AnyDesk, a legitimate remote access tool.
Remote access through AnyDesk deploys DarkGate
Once attackers gain remote access through AnyDesk, they proceed to deploy DarkGate malware, which possesses several dangerous capabilities, including:
- Evading Windows Defender detection.
- Extracting browser history.
- Hijacking Discord tokens.
- Implementing remote access capabilities.
- Performing keylogging and cryptomining activities.
Recent campaign specifics
The current campaign primarily targets organizations that have enabled External Access in Microsoft Teams, a feature that allows communication with users outside the organization. Security researchers at Trend Micro have documented that the attackers are specifically exploiting this functionality to establish initial contact with potential victims.
Expert analysis

Security experts note that this attack represents a significant evolution in social engineering tactics. The use of Microsoft Teams as an attack vector is particularly concerning because many users inherently trust communications through official corporate channels. This trust makes the social engineering aspect of the attack more effective than traditional email-based phishing attempts.
Mitigation strategies
Organizations can protect themselves by implementing several key security measures:
- Disabling External Access in Microsoft Teams unless absolutely necessary.
- Implementing strict verification protocols for third-party technical support.
- Establishing cloud vetting processes for remote access tools.
- Deploying multi-factor authentication.
- Maintaining whitelists of approved remote access applications.
Broader impact

This attack campaign marks a notable shift in cybercriminal tactics following the disruption of the Qakbot botnet in August. Cybercriminals have increasingly turned to DarkGate as their preferred malware loader for initial network penetration. The sophistication of this attack, combining social engineering with legitimate business tools, represents a concerning trend in modern cyber threats.
Security researchers continue to monitor this threat actively, with multiple cybersecurity firms documenting new variations of the attack. The campaign has particularly targeted organizations in the Americas region, though the threat is considered global in scope.
This emerging threat underscores the critical importance of maintaining robust security awareness training programs and implementing comprehensive security measures, especially for organizations relying heavily on collaborative tools like Microsoft Teams.
About The Author
Discover more from Microsoft News Now
Subscribe to get the latest posts sent to your email.