INTEL_REPORT
Palo Alto Networks Unit 42 · published 6/8/2026, 11:00:45 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
When “Hi, This Is IT” Comes Through Microsoft Teams Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42 . When “Hi, This Is IT” Comes Through Microsoft Teams Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General When “Hi, This Is IT…
https://unit42.paloaltonetworks.com/microsoft-teams-phishing
sha256:a26d9fdcaf074f1e4d4832543923708870767b48eb3e7261b98f0959a6ed4360
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| cve | CVE-2026-0257 | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.