Blog, Endpoint Security Blog, LOGON Blog
ConvoC2: A Red Teamer’s Tool to Exploit Microsoft Teams for Remote Command Execution
LOGON BLOG
ConvoC2: A Red Teamer’s Tool
to Exploit Microsoft Teams for Remote Command Execution

Author: Jaqueline Fong, LOGON Software Asia
On December 15, 2024, cybersecurity enthusiasts and professionals were introduced to ConvoC2, a stealthy Command-and-Control (C2) infrastructure tool tailored for Red Team operations. ConvoC2 reveals how cyber attackers can exploit trusted collaboration platforms like Microsoft Teams to execute system commands remotely on compromised systems. This innovative tool underscores the vulnerabilities within widely adopted collaboration tools, posing new security challenges for organizations.
How ConvoC2 Operates
ConvoC2 exploits Microsoft Teams by leveraging hidden data within Teams messages to covertly infiltrate and exfiltrate sensitive data. Here is an outline of its operational methodology:
Command Injection via Hidden Tags
- Commands are embedded in hidden tags within Teams messages.
- Even if a user does not accept the attacker’s chat request, the commands remain cached in Teams logs, enabling eventual execution.
Data Exfiltration through Adaptive Cards
- Exfiltrated data is encoded within Adaptive Cards’ image URLs.
- Outbound HTTP requests are triggered to send the data to an attacker-controlled C2 server.
Stealth Tactics
- No direct connection exists between the attacker and the victim, as communication is routed through Microsoft’s servers.
- Antivirus and traditional monitoring tools rarely inspect Teams logs, enhancing ConvoC2’s stealth.
By leveraging these techniques, attackers can operate without raising alarms, even within robustly monitored environments.
Architectural Overview and Demonstration
The architecture of ConvoC2 demonstrates its innovative approach:
- Server Setup: The ConvoC2 server coordinates agents deployed on compromised systems.
- Victim Systems: Systems running Microsoft Teams (both new and old versions) can be compromised.
- Cross-Organization Potential: Attackers external to the victim’s organization can exploit Teams, emphasizing the need for robust monitoring.
Requirements and Setup
To deploy ConvoC2, the following prerequisites are necessary:
Server and Agent Setup
- Install the ConvoC2 server and agent on a public-facing system.
Teams Channel Configuration
- Create a Teams channel and set up an Incoming Webhook to receive data.
Victim Identification
- Use a web proxy to intercept Teams API requests and retrieve victim IDs and Bearer tokens.
Execution Environment
- Ensure Microsoft Teams is active (even in the background) on the victim’s system.
- Configure HTTP traffic on port 80 for communication between the server and agents.
Defensive Measures for Organizations
Organizations must adopt proactive measures to defend against threats like ConvoC2:
- Enhanced Monitoring: Regularly audit Microsoft Teams environments and logs for unusual activity.
- Endpoint Detection and Response (EDR): Deploy advanced EDR tools capable of inspecting Teams logs and identifying anomalies.
- Collaborative Security: Work with cybersecurity communities to uncover vulnerabilities and share threat intelligence.
How LOGON Software Asia Can Help
At LOGON Software Asia, we understand the complexities of modern cybersecurity challenges. We empower organizations in Asia to tackle emerging threats with top-tier Endpoint Security solutions.

By deploying advanced tools, organizations can:
- Monitor endpoints and collaboration platforms effectively.
- Detect and neutralize hidden threats, including those exploiting ConvoC2 techniques.
- Strengthen overall security posture against sophisticated attacks.
Contact us today to learn how we can help you stay ahead of evolving threats.


