New threat: cyber criminals posing as helpdesk staff

You’re at your desk and suddenly your inbox explodes with spam. Like, a ridiculous amount. Before you can even think about what to do, you get a message on Microsoft Teams from someone claiming to be from IT support. They say they’ve noticed the spam issue and want to help you fix it.

Hey, IT support is on the ball!

Except the same people flooding your inbox with spam are the ones offering to “fix” it.

Google’s Threat Intelligence Group just identified a group doing exactly this (they’re calling them UNC6692, but the name doesn’t really matter). What matters is the playbook they’re using, because it’s working.

How the scam works

The whole thing is orchestrated:

  1. They create chaos – Flood someone’s email with junk
  2. They offer the solution – Pop up on Teams pretending to be IT support
  3. They send a “fix” – A link to something called a “Mailbox Repair Utility”
  4. They harvest credentials – When the person tries to log in to “fix” their mailbox
  5. But here’s where it gets sneaky: When you enter your password on their fake page, it tells you it’s wrong. Then you try again, and it’s still wrong. So you try a third time.

Why? Because now they’ve captured your password three times, which means even if you mistyped it once, they’ve probably got the right one. Plus, the rejection makes the whole thing feel more real—because legitimate systems reject wrong passwords, right?

Once they’re in, they’re installing malware and getting themselves set up to access whatever they want in your network.

Why this one’s different

This isn’t someone sending a sketchy email hoping you’ll click. This is:

  • Creating a problem that makes their “solution” seem urgent and welcome
  • Using platforms people trust – Microsoft Teams, cloud services that look completely legitimate
  • Playing the long game – They’re not just grabbing a password and running; they’re establishing persistent access

The really frustrating part? They’re using legitimate cloud services to host their malicious stuff. That means it looks like normal business traffic. Your traditional security tools that watch for “known bad” websites or suspicious downloads? Those might not even notice because everything appears to come from trusted platforms.

What you need to know

First, recognize the psychology …

When something goes wrong and someone immediately offers to fix it, we’re relieved. We let our guard down. These attackers are banking on that reaction. They’re literally weaponizing your employees’ desire to solve a problem and get back to work.

Second, the trust factor…

Most people don’t question a Teams message from IT. Why would they? That’s how IT communicates. But now we’re in an AI world where “appearing legitimate” is easier than ever for attackers because it’s personalized. They are targeting specific companies who hold sensitive financial and legal data for their clients.

Third, the scale of impact…

This isn’t about one stolen password. Once they’re in with legitimate credentials, they can move around your network, install tools to maintain access, and look like any other employee doing their job. By the time you realize something’s wrong, they’ve been poking around for days.

What can you do?

Verification protocols

If anyone contacts you claiming to be IT support—especially if it’s about a sudden problem you just noticed—there’s going to be a secondary verification step. Call IT directly using a number you already have. Don’t use contact info from the person reaching out to you.

Behavioral awareness

Watching for patterns that don’t make sense. Someone logging in from their normal location but suddenly downloading tools they’ve never used? Installing browser extensions? Accessing systems they don’t normally touch? Those all trigger alerts now.

Faster response loops

When something gets flagged, move quickly. The window between “they got credentials” and “they’ve established persistent access” is narrow, and we’re focused on catching things in that gap.

What should you do?

  • If IT contacts you out of nowhere about a problem—especially if that problem just started happening—pause. Verify through a different channel. Yes, it might be legitimate. It might also be someone who just caused the problem they’re claiming to fix.
  • If you’re asked to click a link to resolve an IT issue, be skeptical. Real IT support can usually fix things without you needing to log into external portals or install utilities.
  • If a login rejects your password multiple times, stop and think. Could be a legitimate system issue. Could also be someone harvesting multiple attempts.

None of this means you should distrust us. It just means we need to add one simple step: verify the person is who they say they are before taking action on unexpected requests. We have a tight-knit team! Slow down just enough to verify that the person offering help is actually on your side. Don’t worry, we work fast to solve your problem, after we introduce ourselves.

The bad guys have figured out that creating urgency and offering immediate solutions is way more effective than sending obviously suspicious emails. They’re banking on the fact that when people are stressed (like dealing with an inbox full of spam), they’ll grab onto any lifeline offered.

As always, if something feels off or you’re not sure, reach out to us directly. We’d rather field a hundred “false alarm” questions than miss one real attack.

Stay sharp out there!

Klaus