1w ago · unit42
Threat actors are increasingly exploiting trusted enterprise collaboration platforms such as Microsoft Teams and Slack to conduct identity phishing, impersonation, credential theft, and malware delivery. These attacks leverage the inherent trust in authenticated communication channels to bypass traditional security controls, using techniques like external federation abuse, social engineering, and malicious third-party integrations. Real-world incidents include APT29 using compromised Teams accounts to distribute credential-harvesting links, a North Korea-linked campaign impersonating Fireblocks during fake job interviews to deliver malware via npm install, and attackers poisoning the Axios npm package by compromising a maintainer through a spoofed Slack environment. Additionally, attackers have used legitimate Slack webhook integrations on compromised appliances to exfiltrate credentials, demonstrating post-compromise persistence through trusted SaaS channels.