VYPR
researchPublished Aug 20, 2026· 1 source

Attackers Exploit Trusted Collaboration Tools for Identity Phishing and Credential Theft

Cybercriminals are increasingly abusing enterprise collaboration platforms like Slack and Microsoft Teams to conduct identity phishing and steal credentials, bypassing traditional security measures.

Organizations are increasingly relying on enterprise collaboration tools for daily operations, making these platforms a prime target for threat actors. A recent report from Unit 42 highlights a significant surge in malicious activity within these trusted communication channels, with alerts related to collaboration tools quadrupling over the past year. Attackers are exploiting the inherent trust users place in platforms like Slack and Microsoft Teams to conduct sophisticated identity phishing, impersonation, credential theft, and social engineering attacks.

These platforms have evolved from simple productivity applications into critical components of the enterprise attack surface. The research indicates that 99% of malicious alerts generated within these environments stem from chat phishing operations. Once an attacker gains access, they can leverage the compromised user's identity and privileges, making their malicious activities appear as legitimate collaboration. This shift poses a significant challenge as traditional security controls often lack visibility into activity occurring within authenticated collaboration sessions, focusing primarily on email and authentication events.

Attackers exploit various features of collaboration platforms to achieve their objectives. These include compromised accounts, external federated organizations, guest accounts, and trusted third-party relationships. The inherent trust in these channels, combined with features like real-time conversations, external federation, and shared workspaces, creates opportunities for misuse. Unlike email, where suspicious requests might raise immediate red flags, similar requests originating from an authenticated collaboration platform can appear routine, lowering a target's guard.

Real-world campaigns demonstrate the multi-stage nature of these attacks. Threat actors use collaboration platforms for initial access, often through identity phishing. For instance, APT29 has been observed using compromised Teams accounts to send links to credential-harvesting pages, impersonating IT support to trick users into visiting phishing sites or approving MFA requests. This technique leverages external federation to initiate conversations with victims, making the phishing attempt more convincing.

Beyond initial access, attackers employ these platforms for stealthy operations, including impersonation and persistence. They can impersonate legitimate users through direct messages or hosted content within the platform. Furthermore, attackers have been documented modifying authentication processes, such as removing multi-factor authentication (MFA) protections and exfiltrating privileged credentials through native integrations like Slack webhooks. This highlights the depth to which attackers are integrating their operations within the trusted workflows of these platforms.

Palo Alto Networks emphasizes that protecting against these evolving threats requires a multi-layered approach. This includes robust identity and access management, strong authentication mechanisms, and enhanced visibility into post-authentication activities within collaboration sessions. Organizations must treat these platforms as integral parts of their identity attack surface and implement appropriate security controls and user education.

To mitigate these risks, Unit 42 recommends several defense strategies. These include strengthening user education on recognizing phishing attempts within collaboration tools, implementing strict access controls and monitoring for suspicious activities, and leveraging security solutions that provide visibility into collaboration platform usage. Products like Cortex XDR and XSIAM, along with various Idira security solutions, are highlighted as beneficial for detecting and defending against these identity-focused attacks.

Synthesized by Vypr AI