Blog Zscaler
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
Collaboration and Support Platforms are the New Attack Surface
Ransomware's most effective entry point in 2026 isn't a weaponized attachment or an unpatched edge device. It's a Microsoft Teams message from what looks like your own IT help desk. According to the ThreatLabz 2026 Ransomware Report, initial access has largely moved off the exploit path and onto the workflow path, where attackers blend into the tools employees use and trust every day. That shift has a consequence that security teams can't afford to underestimate: when ransomware enters through collaboration and remote support platforms, the attack surface expands to include every governance decision ever made about those tools. Defending it requires controls built for that reality.
The Playbook That Keeps Working
The sequence is consistent enough to call it a new standard. It starts with spam bombing: a sudden flood of legitimate-looking marketing emails fills a target's inbox. The volume is disorienting, and that's intentional. The spam itself isn't malicious, it's the setup. While the victim is confused and looking for an explanation, the attacker contacts them through Microsoft Teams, using a fraudulent Microsoft 365 tenant with a subdomain carefully crafted to look like internal IT support. The connection feels credible. Of course IT is reaching out. Look at what just happened to your inbox.
From there, the victim is walked through granting remote access via a legitimate tool: Microsoft Quick Assist, AnyDesk, or TeamViewer. The attacker now has a foothold. What happens next varies by operator, but the opening sequence is almost always the same.
ThreatLabz tracked three distinct initial access brokers using this playbook in 2025 and 2026, each deploying entirely different malware after gaining access. One deployed a new custom malware family called GoGRPC, using gRPC over HTTP/2 for command-and-control to blend into normal enterprise traffic. A second used a Java-based remote access trojan that communicated with attackers via Google Drive APIs, a platform so common in corporate environments that the malicious traffic was nearly indistinguishable from legitimate use. A third, operating as an initial access broker for Payouts King ransomware, added a fake spam filter update website on AWS infrastructure to steal Microsoft 365 credentials before deploying a modified Havoc payload, later evolving to a custom browser extension-based implant called Edgecution that ran silently inside a headless Microsoft Edge process.
Three brokers. Three different toolchains. One opening sequence. The playbook persists even as the malware behind it evolves.
Trust is the Vulnerability
What makes this attack pattern so difficult to stop at the point of execution is that it doesn't exploit a software flaw, it exploits a human one.
ThreatLabz analyzed 351 victims linked to a prominent ransomware campaign and found that 62% held manager-level titles or above. More than 75% worked in finance, sales, operations, HR, or marketing, the functions that keep a business running and hold the information an organization can least afford to expose. These are not the most technically privileged accounts in the organization. They are, however, among the most trusted. A message or file-share request from a manager carries inherent credibility, and attackers know it. Compromise one, and the ripple effect extends through every workflow that person touches.
Generative AI is making target selection sharper and the social engineering itself harder to detect. Attackers can use AI to identify high-value employees faster, tailor outreach more convincingly, and generate new tooling variants with less manual effort. ThreatLabz assessed that an initial access broker in the Payouts King campaign likely used AI to produce multiple functional iterations of a malicious batch script, accelerating the operation and making each variant harder to match against known signatures.
The result is an attack that looks, at nearly every stage, like something routine.
The Risk Has Moved to the Workflow Layer
Traditional security models treat the risk as residing at the perimeter, in the executable, or at the endpoint. An attacker exploits a vulnerability, delivers a payload, gets caught by detection. That mental model doesn't map cleanly onto what ThreatLabz is observing.
When Microsoft Quick Assist is the delivery mechanism and Teams is the social engineering channel, the attack surface includes the governance decisions your organization has made or hasn't made about those tools. Which remote support applications are sanctioned? Who can initiate a session? Is external Teams access from unknown tenants permitted? Are employees trained to recognize the spam-bombing-plus-IT-contact sequence?
Those questions have always been IT governance questions.
They're now security questions. The infrastructure layer reinforces the problem. The Payouts King broker hosted both the fake spam filter update site and C2 servers on AWS, trusted cloud infrastructure that many network controls treat as implicitly trustworthy. The Java-based RAT from the second case study used Google Drive APIs for all command-and-control activity, with authentication secrets hardcoded into the payload. Blocking those communications without also blocking legitimate Google Drive access is not straightforward. Attackers aren’t just abusing trusted tools to gain entry, they're using trusted infrastructure to maintain control and move data out.
When attack infrastructure and business infrastructure are functionally indistinguishable, detection requires a different layer of visibility than most organizations have applied to these workflows.
Closing the Gaps Attackers Count On
Addressing a workflow-layer attack surface requires governance, policy enforcement, and inline inspection working together, not just endpoint controls applied after the fact.
Govern the Entry Points
Start with the tools themselves. Define a sanctioned list of remote support applications and block the rest at the policy level. If Quick Assist, TeamViewer, and AnyDesk aren't explicitly governed, they're implicitly open to abuse. Use Teams external access and federation controls via the Teams admin center's External Access policy to allowlist which external organizations or domains can contact your users, reducing exposure to fraudulent ‘help desk’ tenants including lookalike onmicrosoft.com tenants. These are configuration decisions, but they have meaningful security consequences.
Enforce Targeted Friction with Zscaler Internet Access
Zscaler Internet Access (ZIA) provides policy enforcement and telemetry (via logs and insights) that security teams can use to identify unusual access patterns—such as new remote support tool usage, suspicious download behavior, or repeated access to newly registered domains. Because many modern attacks blend into normal-looking SaaS traffic, Zscaler's SSL inspection and inline security controls can provide visibility and enforcement for suspicious downloads, known-bad destinations, and anomalous traffic patterns, even when traffic is going to commonly trusted services.
Back it with Zscaler Sandbox Inspection
Zscaler Cloud Sandbox can analyze suspicious files transiting sanctioned workflows, helping stop unknown malware before it reaches endpoints. The modified Havoc payloads used in Payouts King attacks were engineered specifically to evade sandbox detection: C2 configuration stored in the Windows registry, bytes stripped from ZIP archives, execution paths that fork based on which security products are present. Cloud Sandbox’s AI-powered behavioral analysis can help catch anomalies like these, identifying malicious behavior regardless of whether the specific payload has been seen before.
Collaboration Tools Aren't Going Away—And This Problem Isn't Either
Microsoft Teams has more than 320 million monthly active users. Remote support tools are essential to how IT operates. Neither is going anywhere, and ransomware operators have already adjusted their playbooks to reflect that permanence.
The organizations most exposed aren't the ones running outdated software, they're the ones that haven't extended their security governance to the platforms that now sit at the center of how work gets done. Enforcing policy around how those tools are used, applying inline inspection to the workflows they enable, and training employees to recognize the social engineering sequences that weaponize them is how the attack surface gets smaller.
For a full breakdown of the initial access playbooks, technical case studies on GoGRPC, Edgecution, and the Google Drive RAT, and a complete ransomware defense checklist, download the ThreatLabz 2026 Ransomware Report.
Cet article a-t-il été utile ?
Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet article de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
En envoyant le formulaire, vous acceptez notre politique de confidentialité.



