KongTuke Initial Access Brokers Microsoft Teams Social Engineering | MSSP Advisory
Critical
DateMay 14, 2026
📋Executive Summary
KongTuke initial access brokers now use Microsoft Teams to conduct social engineering attacks, gaining persistent network access in under five minutes. The attackers pose as IT support staff through Teams messages and calls, convincing targets to install remote access tools like AnyDesk or TeamViewer. This represents a shift from traditional email phishing to direct Teams communication channels.
⚠️Why It Matters for MSSPs
Your RMM and PSA platforms rely on the same authentication systems that KongTuke compromises through Teams attacks, putting your entire client access infrastructure at risk. Every client running Microsoft Teams without proper social engineering controls becomes a potential breach vector that reflects back on your security advisory role.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Phishing
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.