Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft.

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Identity has become a primary security boundary for most organizations, reducing the ability to solely trust other boundaries once associated with corporate networks. With the adoption of software-as-a-service (SaaS) on the rise, people are shifting to platforms for communication and collaboration. In addition to typical email-based phishing, attackers increasingly misuse trusted collaboration platforms to conduct identity phishing, impersonation, credential theft, malware delivery and social engineering.
Unit 42 researchers found that 99% of the alerts generated related to chat or voice phishing operations, indicating that attackers often gain access to these environments through targeted phishing operations. We also provide practical recommendations for detecting and defending against identity-focused attacks targeting enterprise collaboration platforms. This reduces a target’s suspicion and increases the effectiveness of identity phishing, impersonation, credential theft and social engineering. The threat actor behind this activity impersonated administrators and employees from targeted organizations and sent phishing links through direct messages, channel mentions and legitimate notifications.
Protecting them requires both strong authentication, and visibility into how trusted identities and communication channels are used after authentication. In our Insights article, "When 'Hi, This Is IT' Comes Through Microsoft Teams" , we discussed how APT29 used compromised Teams accounts to send links to credential-harvesting pages . In this case, the threat actor sent a RAR file via a link to a victim in a Teams chat. The attackers relied on recognized identities, legitimate services and familiar business processes to obtain credentials or persuade victims to take actions that enabled identity compromise.
This changes the role that collaboration platforms play within enterprise security. We examine how threat actors leverage trusted communication channels and review identity abuse techniques. Requests that might appear suspicious in an email can appear routine when delivered through an authenticated collaboration platform. As organizations adopt more SaaS collaboration platforms, they should treat these environments as part of the identity attack surface.
Security teams should review unexpected Slack webhook traffic, uncommon user agents and webhook activity from systems without an approved Slack integration. Where possible, limit external communications to trusted organizations, and implement a process to review guest accounts regularly and remove unnecessary access. Security teams should monitor for behavior that could indicate identity compromise, including unusual messaging activity, unexpected file sharing or communications with unfamiliar external tenants.
What changed
Recent campaigns demonstrate that attackers use collaboration platforms in multiple stages of identity-focused attacks, from initial access to post-compromise operations.
We reported that attackers misuse external federation in Teams to initiate conversations with victims while impersonating IT support or other trusted personnel.
Unlike commonly-seen email phishing, some collaboration platforms support interactive communication.
Attackers use impersonation to exploit trust in collaboration platforms and gain access to enterprise identities, posing as known individuals, trusted organizations or support personnel.
Each of these campaigns used impersonation through trusted collaboration workflows.
Instruct people to verify high-risk requests through an approved secondary channel, such as a known phone number, ticketing system or documented internal process.
Who is affected
After a successful compromise, attackers can then communicate using the identity and privileges of the compromised user.
Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team .
Employees use these platforms to exchange messages, share files, coordinate projects and communicate with colleagues, customers and business partners.
Organizations typically connect collaboration platform access to their identity provider, and people rely on these platforms for trusted, authenticated communication.
Attackers can exploit compromised accounts, trusted business relationships or authorized external access to interact with victims through legitimate communication channels.
When a collaboration account is compromised, attackers inherit the identity context of that user, including their permissions, relationships and ongoing conversations.
Why this matters
Unit 42 researchers found that 99% of the alerts generated related to chat or voice phishing operations, indicating that attackers often gain access to these environments through targeted phishing operations.
We also provide practical recommendations for detecting and defending against identity-focused attacks targeting enterprise collaboration platforms.
This reduces a target’s suspicion and increases the effectiveness of identity phishing, impersonation, credential theft and social engineering.
The threat actor behind this activity impersonated administrators and employees from targeted organizations and sent phishing links through direct messages, channel mentions and legitimate notifications.
Note that attackers may avoid sending files through Teams because doing so creates an additional detection point through Safe Links/Safe Attachments, instead directing victims to websites or scripts during calls.
The attacker can then access enterprise and cloud services with the privileges and identity context of the compromised user.
The technical picture
Protecting them requires both strong authentication, and visibility into how trusted identities and communication channels are used after authentication.
In our Insights article, "When 'Hi, This Is IT' Comes Through Microsoft Teams" , we discussed how APT29 used compromised Teams accounts to send links to credential-harvesting pages .
In this case, the threat actor sent a RAR file via a link to a victim in a Teams chat.
The attackers relied on recognized identities, legitimate services and familiar business processes to obtain credentials or persuade victims to take actions that enabled identity compromise.
One script retrieved the password of a privileged identity, and another script modified security settings and disabled two-factor authentication for a privileged account.
This activity combined identity persistence and credential exfiltration with a legitimate SaaS integration.
Because these platforms are integrated with enterprise identities, security controls should focus on both preventing identity compromise and detecting misuse after authentication.
Identity protections should also extend beyond authentication.
How organizations are responding
This changes the role that collaboration platforms play within enterprise security.
We examine how threat actors leverage trusted communication channels and review identity abuse techniques.
Requests that might appear suspicious in an email can appear routine when delivered through an authenticated collaboration platform.
As organizations adopt more SaaS collaboration platforms, they should treat these environments as part of the identity attack surface.
One of the most common techniques is identity phishing through enterprise collaboration platforms.
Okta Threat Intelligence has also documented the technique of identity phishing through attacker-controlled Slack workspaces .
What defenders should do now
Security teams should review unexpected Slack webhook traffic, uncommon user agents and webhook activity from systems without an approved Slack integration.
Where possible, limit external communications to trusted organizations, and implement a process to review guest accounts regularly and remove unnecessary access.
Security teams should monitor for behavior that could indicate identity compromise, including unusual messaging activity, unexpected file sharing or communications with unfamiliar external tenants.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.