ms teams is now a C2 (command-and-control)

ms teams is now a C2 (command-and-control)

Source: YouTube · John Hammond · published Mar 18, 2025 · 18:29

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

Convo C2 is a command and control tool that uses Microsoft Teams as a covert channel for executing system commands on compromised hosts, making detection difficult since communications appear as legitimate Microsoft traffic 0:13.

Key Takeaways:
• The tool works by infiltrating data into hidden span tags in Microsoft Teams and exfiltrating command outputs through captive card image URLs 0:24
• Security solutions struggle to detect this activity because victims only communicate with Microsoft servers, not directly with attackers 0:49
• Setting up Convo C2 requires a Linux server, a Teams channel with webhook, and extracting various IDs and tokens using a proxy tool like Burp Suite 9:12
• The tool successfully demonstrates remote command execution through Microsoft Teams in a test environment 15:04

This innovative C2 approach showcases how trusted platforms like Microsoft Teams can be leveraged for post-exploitation persistence while evading traditional security defenses 17:52.

Sources:

  • 0:13 Introduction to Convo C2 as a Microsoft Teams-based command and control tool
  • 0:24 Explanation of how data is hidden and exfiltrated through Teams
  • 0:49 Discussion on why detection is difficult for this type of attack
  • 9:12 Setup requirements for Teams channel and webhook configuration
  • 15:04 Demonstration of successful command execution through Teams
  • 17:52(https://www.youtube.com/watch?v=F

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

command and control infrastructure that allows red teamers to execute system commands on compromise hosts through Microsoft teams this is convo C2 a tool and project recently released I think about November of 2024 that is literally a command and control Channel over Microsoft teams it's actually really interesting how this works it infiltrates data into hidden span tags in Microsoft teams and exfiltrate command outputs in a captive card images URLs triggering out-of-bound requests to a command and control server this means there is no direct communication between the victim and the attacker and the victim only sends messages or HTTP requests to Microsoft online Microsoft servers to handle Microsoft teams so antivirus and other EDR or Security Solutions might not catch this thing detection…