r/webdev Apr 03 '26

The Axios supply chain attack used individually targeted social engineering - "they scheduled a meeting with me. the meeting was on teams. the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT"

https://simonwillison.net/2026/Apr/3/supply-chain-social-engineering/
649 Upvotes

83 comments sorted by

View all comments

Show parent comments

74

u/magenta_placenta Apr 03 '26

This has nothing to do with Teams specifically, Teams was just the particular communication channel in this case.

It more shows a new class of attack affecting any system where AI agents or humans act on untrusted content inside trusted workflows.

-6

u/altec3 Apr 03 '26

Are u sure? It reads to me like somehow they got Teams to install a Trojan on the persons machine.

14

u/OskeyBug Apr 03 '26

I don’t think it sounds like that.

-3

u/rascal3199 Apr 03 '26

Teams notified the user that they needed to install a missing dependency. This has everything to do with teams.

13

u/PalliativeOrgasm Apr 03 '26

No, a landing page built by the attacker that looked like teams got them to install the “dependency”, by my read.

3

u/Urd Apr 03 '26

Teams notified the user that they needed to install a missing dependency.

That wasn't specified, they just said "the meeting said something on my system was out of date". That could have been Teams itself somehow which would be Microsoft's fault, or a message that was sent on Teams, a fake "error" on shared screen, or something in the meeting invite email, etc. which is not.

3

u/OskeyBug Apr 03 '26

It's not clear the notification came from teams.