A US Navy red team member releases TeamsPhisher, which leverages an unfixed Microsoft Teams bug to send malware from an account outside a targeted organization
Bill Toulas / BleepingComputer :
Context & Ripple Effects
Teams has been an attack surface before: back in April 2020 Microsoft patched a Teams flaw that let attackers hijack accounts by sending malicious links or GIFs, and researchers have since shown how trusted platforms get repurposed for delivery — including Trend Micro's demonstration of malware distribution through GitHub Codespaces' port forwarding.
What is new here is who built the tool and its status: TeamsPhisher comes from a US Navy red team member and exploits a bug that remains unpatched, letting an attacker outside an organization push malware through Teams' own external-messaging path. It follows the pattern of government-grade offensive tooling going public, the same dynamic that later prompted FireEye to ship a free auditing tool so defenders could check for SolarWinds-era techniques.
First-order effects
- Organizations that allow external Teams contacts now face a working, publicly available delivery method for malware from outside their tenant, until Microsoft ships a fix.
- Microsoft is under immediate pressure to patch the underlying bug, since the exploit path runs through a feature it controls rather than user error or phishing.
Second-order effects
- Security teams and vendors will be pushed to treat inbound external Teams messages as an attack vector on par with email, driving detection and policy changes around external collaboration settings.
- Other red teams and penetration-testing shops gain a ready-made technique, compressing the lag between government offensive research and mainstream adversary use.
Third-order effects
- If the pattern holds, collaboration platforms will keep getting weaponized through their legitimate features rather than classic vulnerabilities, forcing platform makers to build external-trust controls in by design — while the release of state red-team tools keeps lowering the barrier for ordinary threat actors.
The trend: Collaboration platforms like Teams are shifting from communication channels to malware-delivery infrastructure, and public releases of government red-team tooling are accelerating that conversion.