Skip to main content

Identity Abuse and Phishing via Enterprise Collaboration Platforms

3 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Threat actors misuse enterprise collaboration platforms to conduct identity phishing, credential theft, and malware delivery against corporate users.
  • Affected systems: Enterprise SaaS collaboration platforms, Microsoft Teams, and Slack environments utilizing external federation or guest access.
  • Remediation: Implement comprehensive monitoring of authenticated collaboration sessions and apply strict controls on external federation and guest accounts.

Advertisement

Overview of Collaboration Platform Identity Abuse

Identity has established itself as a primary security boundary for most organizations, reducing the ability to solely trust perimeter defenses associated with corporate networks. As organizations adopt software-as-a-service (SaaS) environments, collaboration tools have become central to daily operations. According to research published by Unit 42, endpoint alerts associated with malicious activity in collaboration tools have more than quadrupled over a twelve-month period. Attackers now leverage these trusted communication channels to execute identity phishing, impersonation, credential theft, malware delivery, and social engineering.

Unlike traditional email vectors, collaboration platforms enable real-time conversations, external federation, guest access, and shared workspaces. Security teams frequently focus monitoring efforts on email and authentication events, leaving limited visibility into internal behaviors within authenticated collaboration sessions. Threat actors exploit this gap to interact with victims using legitimate communication pathways, reducing user suspicion and increasing the success rate of malicious campaigns.

Analysis of Attack Techniques and Tactics

Attackers target collaboration environments through compromised accounts, external federated organizations, guest accounts, or trusted third-party relationships. Researchers found that ninety-nine percent of alerts generated in these scenarios relate to chat phishing operations, indicating that attackers typically gain initial access through targeted phishing before pivoting to collaboration tools. Once inside, malicious actors communicate using the identity and privileges of the compromised user, making malicious activity appear as normal operational traffic.

Prominent campaigns highlight the versatility of these techniques across multiple intrusion stages:

  • Credential Harvesting: Campaigns documented by Unit 42 demonstrate how groups such as APT29 misuse external federation in Microsoft Teams to impersonate IT support personnel, guiding victims to credential-harvesting pages or prompting fraudulent multifactor authentication (MFA) approvals.
  • Adversary-in-the-Middle Proxies: Okta Threat Intelligence identified similar tactics utilizing attacker-controlled Slack workspaces. Threat actors impersonated administrators to distribute phishing links via direct messages and channel mentions, routing victims to adversary-in-the-middle proxies designed to capture corporate credentials and session tokens.
  • Malware Delivery: Attackers also use chat interfaces to transmit malicious archives containing dynamic link library (DLL) side-loading payloads, initiating local execution when unsuspecting users open transferred files.

Actionable Recommendations and Mitigations

Defenders must treat SaaS collaboration platforms as an expansion of the enterprise identity attack surface rather than simple productivity applications. Organizations should prioritize the following defensive measures:

  • Enhance Session Visibility: Deploy security monitoring solutions capable of inspecting activity within authenticated collaboration sessions, focusing on anomalous file transfers, external guest additions, and unexpected federation requests.
  • Tighten Federation Controls: Restrict external federation and guest access policies to verified partner domains to limit the avenues through which external actors can initiate direct messages with employees.
  • User Awareness Training: Train employees to verify out-of-band requests received via chat applications, especially those originating from external tenants or demanding credential re-authentication and software installation.

Related: Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware, ClickFix Attacks Deliver macOS Stealer Targeting Crypto

Advertisement

Advertisement