Instant messenger (IM) (original) (raw)

Summary

Instant messenger (IM) platforms are now the core of corporate communications and the place where most work-related communication takes place. Attackers are targeting both business IM platforms like Slack and Teams, as well as IM platforms like WhatsApp and Signal that are used for both business and personal purposes.

Delivering phishing links via IM platform evades traditional email-based controls while also taking advantage of the fact that users do not expect to be served phishing links via IM platforms — particularly business IM like Slack or Teams.

It is no longer possible to message Slack and Teams users as an external user without first configuring external/guest access and issuing an invitation to join either the tenant or specific channels/workspaces within the tenant. However, attackers have successfully leveraged IM by:

Creating an attacker-owned Slack or Teams tenant and inviting target users to join your tenant.

Examples

Further reading