Hidden Identity Risks in Teams and Slack

0
2

Key Takeaways

  • Attackers who gain control of a legitimate Microsoft Teams or Slack account can blend phishing, credential theft, and malware delivery into ordinary chat traffic, bypassing email‑focused defenses.
  • State‑linked groups such as APT29 (Midnight Blizzard/Cozy Bear) and North Korea‑linked “Contagious Interview” actors routinely impersonate IT support, recruiters, or trusted admins inside compromised collaboration sessions.
  • Multi‑factor authentication, conditional access, and session‑risk scoring stop account takeover but do not prevent misuse of an already‑authenticated session; the attacker inherits the user’s identity context and can send files, approvals, or webhook posts that appear routine.
  • Persistent abuse is possible: compromised appliances or scripts can use built‑in Slack/webhook integrations to exfiltrate data without installing separate malware.
  • Effective mitigation requires a layered approach: verify high‑risk chat requests through a separate channel, stream collaboration telemetry to a SIEM for correlation, and actively hunt for unauthorized outbound webhook traffic from systems lacking approved integrations.

Overview of the Identity Security Gap
Unit 42, Palo Alto Networks’ threat‑research team, defines the “identity security gap” as the blind spot that appears once an attacker possesses a valid collaboration account in Microsoft Teams or Slack. Because the session has already passed MFA, conditional‑access, and login‑screen checks, any subsequent chat‑based request—whether a file transfer, credential prompt, or software install—appears as routine teamwork. Email‑centric monitoring tools never see this activity, allowing attackers to operate under the guise of legitimate collaboration. The gap has grown sharply: endpoint alerts tied to collaboration tools more than quadrupled in a year, with 99 % of those alerts traced to chat‑based phishing.


APT29’s IT‑Support Phishing Via Compromised Teams Accounts
APT29, tracked by Microsoft as Midnight Blizzard and by CrowdStrike as Cozy Bear, has been observed launching phishing campaigns from inside compromised Microsoft Teams accounts. Posing as IT support, the attackers open a chat with an employee, then guide the target toward a credential‑harvesting page, a push for MFA approval, or a prompt to install remote‑access software. Because the message originates from an authenticated, federated Teams tenant, it reads as legitimate internal communication, and traditional email‑based controls never trigger. This technique lets APT29 harvest credentials and gain footholds without needing to breach perimeter defenses.


Parallel Tactics in Compromised Slack Workspaces
The same identity‑phishing playbook appears in Slack. Okta Threat Intelligence has documented attackers who seize control of Slack workspaces—either via compromised accounts, external federated tenants, guest accounts, or trusted third‑party relationships—and then impersonate workspace admins. These fake admins share adversary‑in‑the‑middle links that capture usernames, passwords, and MFA tokens. Unit 42’s telemetry shows the abuse spanning all these vectors; in one Teams case, a victim accepted a RAR file, opened it, and side‑loaded a malicious DLL masquerading as a Windows language pack before endpoint detection flagged it. The core idea remains: abuse the trusted identity inside the chat platform to deliver payloads that look like normal work.


Abuse of the Hiring Pipeline: Contagious Interview Campaign
Attackers also weaponize collaboration tools within recruitment processes. In January 2026, Fireblocks, a digital‑asset infrastructure firm, disclosed a campaign where threat actors posed as the company’s own recruiters and hiring managers. They conducted fake Google Meet interviews, then gave candidates a code‑review task whose npm install step executed malware. Fireblocks attributed the activity to the North Korea‑linked “Contagious Interview” operation. Notably, the credential theft required no software exploit; the attackers relied solely on a believable conversation delivered through a trusted platform to lure victims into executing malicious code.


Why Existing Controls Fail: The Blind Spot Inside Authenticated Sessions
MFA, conditional access, and session‑risk scoring dramatically reduce the odds of initial account compromise, but they do not stop an attacker who already holds a valid session. Once inside, the attacker inherits the user’s full identity context: permissions, standing relationships, and ongoing conversations. A file transfer or approval request that would raise suspicion in email looks like ordinary work when it arrives in an authenticated chat. Consequently, email‑centric monitoring cannot detect this abuse, and the identity itself becomes the attack surface that security teams often underrate.


Persistence Example: Firewall‑VPN Appliance Exfiltration via Slack Webhook
A December 2025 investigation by CERT Polska illustrates how attackers turn trusted integrations into post‑compromise infrastructure. After compromising firewall‑VPN appliances at a Polish manufacturer, the adversary planted scripts that weekly pulled a privileged account’s password and disabled two‑factor authentication. A third script then posted the stolen data to a Slack channel the attacker controlled, using the appliance’s own built‑in Slack webhook. Because the webhook was an approved integration, no separate malware was needed; the legitimate channel became the exfiltration tool. This case shows how federation, webhooks, and native integrations—features that make collaboration platforms productive—are exactly what attackers inherit and repurpose for stealthy data theft.


Extending Identity Security to the Collaboration Layer: Verification
To close the identity security gap, organizations should treat collaboration security as a sequential process: first shrink exposure, then verify requests that cannot be monitored directly, and finally instrument the remaining activity for visibility. Unit 42’s guidance is explicit: users must never approve an MFA prompt, install remote‑access software, or surrender credentials based solely on a chat message. Any such request should be routed to a known phone number, ticketing system, or other out‑of‑band channel. This simple verification step would have blocked the APT29 IT‑support chats before they could succeed.


Feeding Collaboration Telemetry to SIEM for Correlation
Sign‑in events, messaging activity, file‑sharing logs, and external‑tenant interactions only reveal identity abuse when correlated across data sources. Feeding this collaboration telemetry into a security information and event management (SIEM) platform enables analysts to spot anomalous patterns—such as a user suddenly sending large files to an external tenant or repeatedly triggering MFA prompts in chat. By treating SaaS security as an identity‑monitoring discipline, the SIEM can catch the 99 % of malicious activity that begins as a chat message rather than an email.


Hunting Unauthorized Webhook Traffic as a Post‑Compromise Indicator
Perimeter firewalls can see outbound webhook requests leaving the network. Security teams should review unexpected calls to collaboration webhook endpoints, look for unusual user agents (e.g., scripts using curl), and flag posts originating from devices that were never configured for alerting. Unit 42 has published a query to detect collaboration tools that spawn a system shell; any hit should be treated as a strong lead for post‑compromise investigation. Proactive webhook hunting turns a trusted feature into a detection opportunity.


Conclusion: Turning Trust into a Detectable Attack Surface
Collaboration platforms earned their place in the modern workplace by making communication fast and seamless. That same trust, however, has become the very surface attackers target when they hijack a legitimate Teams or Slack session. By implementing out‑of‑band verification for high‑risk chat requests, consolidating collaboration logs into a SIEM for correlation, and actively hunting for rogue webhook traffic, organizations can shift the balance: the next APT29 operator who opens a Teams chat as IT support will encounter a callback to a known number, a correlated alert, and an unapproved webhook—no longer a clean path to a stolen session. Through these measures, the identity security gap can be closed, and collaboration tools can remain productive without becoming a blind spot for attackers.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here