Hackers Registered New Domain with Exact Microsoft Teams Interface to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A newly registered website is copying the Microsoft Teams login page and full user interface, raising concerns about a phishing attempt aimed at stealing work account credentials.

The domain, teams-online[.]com, uses the name of the widely used meeting platform to make a fake site look like a normal place to sign in. The alert says the domain was only four days old when examined. Microsoft Defender reportedly showed zero detections at that time.

That finding is a snapshot from the reported analysis, not proof that every Microsoft security service missed the site or that its detection status remains unchanged.

Security researcher Steven Lim, known on X as @0x534c, identified the suspicious domain in a threat alert posted on October 8, 2026. Lim said the website was actively mimicking the full Teams login and user interface.

He urged organizations to add the domain to their tenant block lists and web filtering policies rather than rely only on endpoint protection.

The available source describes a phishing website, not a confirmed malware infection. It does not name a malware family, show a downloaded payload, or explain how submitted login details are collected.

It also provides no victim count, attacker identity, or evidence that the operators have accessed Microsoft systems. Those limits matter when judging the scope of the threat.

Hackers Registered New Domain with Exact Microsoft Teams Interface

A copied Teams screen targets the trust employees place in a tool they use every day. The page can look familiar while the address belongs to someone else.

In credential phishing, the attacker tries to persuade the user to enter an email address and password into that false login screen, exposing details intended for a real service.

Lim’s report does not establish how people reach this particular website. Email links, chat messages, search results, and meeting invitations should not be presented as confirmed delivery routes.

However, Microsoft has documented phishing through Teams meetings, chats, and calls, showing why a familiar collaboration brand deserves the same care as an unexpected email requesting account access.

Related Cybersecurity News coverage of blob URLs and Microsoft Teams shows how other operators have built fake login pages inside a browser.

Its report on the Tykit phishing kit describes another Microsoft 365 login imitation. These are useful comparisons for understanding brand abuse, but there is no evidence linking either operation to the domain Lim flagged.

Other reporting on Teams impersonation and unauthorized access covers fake meeting recordings used to prompt remote access tool downloads.

Coverage of passkey-themed phishing describes lookalike sign-in pages and stolen cloud sessions. Together, these cases show that similar branding can support different attack paths; they do not prove that this newly reported website installs software or steals session tokens.

Microsoft’s guidance on identity attacks explains that some phishing sites sit between the user and a real login service. This method, called adversary-in-the-middle phishing, can capture session tokens as well as passwords.

Lim’s alert does not confirm that technique here. A copied interface alone cannot establish whether an attacker can bypass multifactor authentication or reuse an authenticated session.

The reported zero detections also needs careful reading: Lim did not publish the Defender product, scan settings, or testing method behind that result.

It therefore cannot support claims of a complete security bypass. The practical concern is narrower: a reported phishing domain may need an explicit block while defenders investigate.

Teams chat restrictions and web filtering address different surfaces, so administrators should choose controls that actually prevent access to the reported website.

The only indicator of compromise supplied for this incident is teams-online[.]com. The source contains no SHA-256, SHA-1, or MD5 hashes, and no IP addresses, file names, or additional malicious URLs.

Security teams should use the reported domain for blocking and investigation without adding indicators from unrelated campaigns. The defanged spelling helps readers share it without creating a clickable phishing link.

Administrators should apply Lim’s recommended domain blocks through supported controls and check relevant web access records for visits.

Any suspected exposure should be reviewed alongside account activity rather than treated as proof of compromise. Microsoft recommends investigating unusual sign-ins, newly added authentication methods, and unexpected cloud data access as connected events when assessing possible identity theft.

For confirmed account compromise, Microsoft’s response guidance calls for resetting credentials, revoking active sessions and refresh tokens, and removing attacker-added authentication methods and mailbox rules.

Longer term, phishing-resistant MFA, including FIDO2 security keys and passkeys, can reduce risk. Employees should verify unexpected login requests through a trusted channel and use known company entry points instead of relying on a page’s appearance.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Registered New Domain with Exact Microsoft Teams Interface to Steal Logins appeared first on Cyber Security News.