
The moment an attacker owns a valid collaboration account, their phishing and file transfers look like ordinary teamwork, and controls built around email and the login screen never fire. Unit 42, the Palo Alto Networks threat-research team, calls this the identity security gap inside authenticated Teams and Slack sessions. Its analysis found endpoint alerts tied to collaboration tools more than quadrupled in a year, and 99% of them traced to chat phishing.
APT29 Runs IT-Support Phishing From Inside Trusted Teams Accounts
APT29, the Russian state-linked espionage group that Microsoft tracks as Midnight Blizzard and CrowdStrike as Cozy Bear, has been messaging employees from inside compromised Microsoft Teams accounts. Posing as IT support, the operators open a chat, then steer the target to a credential-harvesting page, a multifactor authentication (MFA) approval, or a remote-access install. Because the request arrives through an authenticated, federated Teams tenant, it reads as routine, and that is the entire point.
The pattern is not limited to one crew. Okta Threat Intelligence has documented the same identity phishing play in attacker-controlled Slack workspaces, where impersonated admins push adversary-in-the-middle links that capture credentials and MFA tokens. Unit 42’s telemetry shows the abuse spanning compromised accounts, external federated tenants, guest accounts, and trusted third-party relationships. In one Teams case, a victim accepted a RAR file, opened it, and side-loaded a malicious DLL disguised as a Windows language pack before endpoint detection caught it.
Attackers run the same trust abuse against the hiring pipeline. In January 2026, Fireblocks, a digital-asset infrastructure firm, disclosed a campaign in which attackers posed as its own recruiters and hiring managers. They ran candidates through a Google Meet interview, then handed over a code-review task whose npm install step executed malware. Fireblocks tied the activity to Contagious Interview, a North Korea-linked operation. The credential theft here needed no exploit, only a believable conversation on a trusted platform.
The Blind Spot Sits Inside Authenticated Slack and Teams Sessions
MFA, conditional access, and session-risk scoring all reduce the odds of account compromise, yet none of them stop an attacker from misusing a session that has already passed those checks. Once a collaboration account falls, the attacker inherits its identity context: the permissions, the standing relationships, and the open conversations. A file transfer or an approval request that would raise an eyebrow in email looks like normal work when it arrives in an authenticated chat. That gap is the identity security problem Unit 42 is describing, and email-centric monitoring cannot see it. We have made the case before that identity itself is becoming the attack surface security teams underrate.
Unit 42 frames 99% of its alerts as chat phishing, an initial-access story. The report’s own persistence case is the more consequential read. In December 2025, CERT Polska, Poland’s national computer emergency response team, investigated compromised firewall-VPN appliances at a Polish manufacturer. An attacker had scripted weekly tasks that pulled a privileged account’s password and disabled two-factor authentication. A third script posted the stolen data to a channel the attacker controlled, using the appliance’s own built-in Slack webhook. The approved integration became the exfiltration tool, with no separate malware required. Federation, webhooks, and integrations make these platforms productive, and they are exactly what an attacker inherits and turns into post-compromise infrastructure.
Extend Identity Security to the Collaboration Layer
Treat these controls as a sequence: shrink the exposure first, verify the requests you can’t monitor directly, then instrument what remains so your security operations team can see abuse that wears a valid identity.
Verify high-risk chat requests through a second channel – Unit 42’s guidance is blunt: users should never approve an MFA prompt, install remote-access software, or hand over credentials on the strength of a message alone. Route any such request to a known phone number or ticket, the step that would have stopped the APT29 IT-support chats cold.
Feed collaboration telemetry to your security information and event management (SIEM) platform – Sign-in events, messaging activity, file-sharing, and external-tenant interactions only expose identity abuse once correlated, and the SIEM is where that happens. This is what turns SaaS security into an identity-monitoring discipline, and how you catch the 99% of activity that starts as a chat message rather than an email.
Hunt outbound Slack and Teams webhook traffic from systems with no approved integration – Perimeter firewalls see these webhook requests leaving the network. Review unexpected calls to collaboration webhook endpoints, unusual user agents such as curl, and posts from appliances nobody wired for alerting. Unit 42 published a query to flag collaboration tools that spawn a system shell, and your incident response teams should treat a hit as a post-compromise lead.
Collaboration platforms earned their trust by making work faster, and that trust is now the identity security surface attackers reach for. Get the verification, correlation, and webhook hunting in place, and the equation changes for the attacker. The next APT29 operator who opens a Teams chat as IT support meets a callback to a known number, a correlated alert, and a webhook nobody approved, not a clean path to a stolen session.
Join our LinkedIn group Information Security Community!









