Email-Bombing-Header1

IT Tips & Tricks

When Phishing Looks Like Your Own IT Department

How email bombing, Microsoft Teams and legitimate remote-support tools can turn one user’s mistake into an enterprise incident.

Published 18 September 2026

The attack doesn’t begin with a flaw in Microsoft Teams. It begins with a flaw in the way we decide whom to trust.

First, Create the Problem

Source-of-the-Problem1

The person creating the crisis may be the same person offering to make it disappear.

During an active inbox flood, the caller appears to possess information that only the real support team would have. The problem itself seems to authenticate the caller, and the user may grant access before your team even knows anything is happening.

Email bombing isn’t always part of the sequence. Microsoft has also observed attackers using pretexts such as security updates, spam-filter repairs, account verification and tasks supposedly required to prevent account deactivation. Whatever the story, the goal is to make immediate compliance feel safer than delay.

Phishing Has Left the Inbox

Voice adds another advantage. The attacker can answer questions, adjust the pretext in real time and keep the user moving through the remote-access process. Verbal instructions also leave less evidence in the Teams chat record.

It’s phishing, but it doesn’t look like the phishing many employees are trained to spot.

It’s phishing, but it doesn’t look like the phishing many employees are trained to spot.

When a Support Workflow Becomes Initial Access

The packages carried harmless-sounding names such as “Hotfix” and “devfix” and were installed through msiexec with the /qn switch, suppressing the installer interface.

The installer staged an encrypted JavaScript implant and, where necessary, downloaded a legitimate portable Node.js runtime to execute it. Using a signed, trusted runtime helped the activity blend into normal enterprise operations while establishing persistent command execution from the user’s LocalAppData directory.

Microsoft also observed persistence through a current-user Run key or Startup-folder shortcut disguised as an update process.

One Employee’s Computer Is Only the Beginning

Remote-Access1

One approved remote session can open a path towards far more valuable systems.

“Don’t Fall for It” Isn’t a Support Protocol

Employees need a reliable way to distinguish legitimate support from impersonation.

That isn’t enough.

Employees need a reliable way to distinguish legitimate support from impersonation. If your help desk contacts people unexpectedly, asks for immediate cooperation and begins remote sessions without an established verification process, attackers can imitate that behavior. The organization has unknowingly supplied the script.

What Your Team Can Control

Make Real IT Easier to Verify

Nope-Just-Nope1

Not on your watch. A callback to a secure number can stop an apparent support request from becoming an enterprise-wide nightmare.

EdV2

LinkTek COO

Ed Clark

Leave a Comment

Please note: All comments are moderated before they are published.





Recent Comments

  • No recent comments available.

Leave a Comment

Please note: All comments are moderated before they are published.