Attackers are increasingly abusing trusted enterprise collaboration platforms including Microsoft Teams, Slack, and Google Meet to steal credentials, impersonate employees, deliver malware, and maintain post-compromise access. Palo Alto Networks Unit 42 reported that alerts tied to malicious activity on collaboration tools increased more than fourfold over the past year, with 99% of those alerts linked to chat-based phishing. The activity reflects a shift from obviously malicious infrastructure to legitimate communication channels that users and defenders often trust by default.
Documented cases include APT29 phishing through Microsoft Teams, adversary-in-the-middle credential theft using attacker-controlled Slack workspaces, the Contagious Interview campaign themed around Fireblocks, the compromise of an Axios npm maintainer, Slack phishing reported by OpenSSF against Linux Foundation communities, and CERT Polska findings on Slack webhook abuse for persistence and credential exfiltration. Researchers said collaboration platforms now form part of the enterprise identity attack surface and urged organizations to tighten guest and federation controls, enforce stronger identity protections, verify sensitive requests through secondary channels, and correlate collaboration, endpoint, and network telemetry in monitoring and incident response.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
In April 2026, OpenSSF reported a campaign targeting members of the Linux Foundation TODO Group Slack workspace and related communities. The actor impersonated a known community leader, sent Slack DMs linking to Google Sites, walked victims through a fraudulent Google Workspace authentication flow, and on macOS also downloaded and executed a binary that could provide system access.
In March 2026, a threat actor used a staged Slack workspace and a staged Teams meeting to socially engineer the lead maintainer of the Axios npm package into installing software that delivered a remote access Trojan. The actor then accessed the maintainer's npm account and published two poisoned Axios versions that caused downstream projects to retrieve and execute a malicious dependency.
In January 2026, Fireblocks disclosed a social engineering campaign impersonating its executives, recruiters, and hiring managers. Targets were moved from social media to Google Meet interviews and instructed to clone a GitHub repository and run npm install, which executed malicious code and downloaded malware.
CERT Polska investigated a December 2025 intrusion at a manufacturing company in Poland where compromised firewall-VPN appliances were modified with weekly scheduled tasks. The scripts retrieved a privileged password, disabled two-factor authentication for a privileged account, and used the appliance's native Slack notification capability to send results to a threat-actor-controlled Slack channel.
Unit 42 published research describing how attackers abuse enterprise collaboration platforms such as Microsoft Teams, Slack, and Google Meet for identity phishing, impersonation, credential theft, malware delivery, and persistence. The report said collaboration-tool-related malicious activity alerts had more than quadrupled over the prior 12 months and that 99% of related alerts were tied to chat phishing operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcemalware.news
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.