Burglars who are invited in are not supposed to be defeated by the locks. Yet that was nearly the fate of a red team at SCRT, the security outfit behind Orange Cyberdefense Switzerland’s technical blog, during an engagement that began in early June 2025. The test was an “assume breach” exercise: a contact on site would fetch and run whatever the testers asked, sparing them the bother of social engineering. They knew the client well, ran regular penetration tests for it during the year, and gave themselves roughly two months to gain a foothold and do some post-exploitation. They reckoned they had a comfortable margin for error. They did not.
The plan was unremarkable by the standards of real-world attacks. The dropper sat on one of the team’s fake websites, chosen for its high reputation and proper categorisation, so as to pass corporate proxy filters. The target user would download a 7z archive via HTML smuggling, extract a signed, well-known executable along with some DLLs, and run it—thereby bypassing Windows’ Mark-of-the-Web protection. A DLL-hijacking trick would then copy the true payload into the user’s AppData folder, where Microsoft Teams would load it the next time it started. At least three actions on the user’s end, none of them suspicious.
The payload itself was a custom implant: nothing flashy, just an encrypted connection back to a command-and-control, or C2, server over HTTPS, some tunnelling capability and a handful of commands for lifting local credentials and running tools remotely. In the team’s lab, which mimicked the client’s known defences, the whole chain survived scrutiny by endpoint detection and response software—download, extraction, hijacking, execution. The implant could even sniff out proxy settings and authenticate transparently with the user’s own credentials.
Then came D-day. On a call with the client’s on-site contact, the team watched the archive arrive on their server, saw it extracted and ran the executable. Nothing visibly happened; the payload was silently copied to its folder. The contact restarted Teams. The app hung for a few seconds, then shut down. On the red team’s server, a single opening packet of a connection attempt appeared—and nothing more. The session never established.
Had the implant been caught by the endpoint software? There was no clear sign of it, and it had briefly reached the server. The team bolted what they describe as a ton of debug logging onto the implant, repacked everything and scheduled another run. The log confirmed only what they already knew: no session. Days of rabbit holes followed, with the client, to its credit, unfailingly co-operative. In one brainstorming session the client let slip the clue that upended everything: their network did not run one web proxy, but two—and the second supported virtual browsing.
The browser that is not there
Virtual browsing starts from the presumption that all web content is guilty. Rather than letting a page load on the employee’s machine, a proxy sends it to a virtual browser inside a container, ideally on separate infrastructure. What returns to the user’s screen is an HTML document generated on the fly—a kind of screenshot of the real page, with all the active content interpreted remotely. The red team had assumed the conventional corporate model, in which a single proxy filters traffic and unwraps encryption; that has been the de facto standard in big organisations for years. A second layer that never lets code touch the endpoint at all is something else entirely. Interactive forms need fiddly, fine-grained exceptions, but a self-contained implant expecting ordinary HTTPS has, as the team admits, no way through.
Workarounds were weighed and discarded. Embedding a headless browser in the implant could interpret the pages the virtual browser produced, and sending data out was easy enough—but retrieving instructions from the C2 server would have meant smuggling them through static HTML tags, a trick too specific to one vendor’s product to be worth building. Side channels offered little: outbound filtering was tight, and DNS, the only protocol that might have slipped through, was heavily monitored.
The escape route, as the team puts it, was right in front of their eyes. Virtual browsing copes poorly with complex applications such as Teams, so administrators must punch exceptions—typically by domain name—past the second proxy. The client network could plainly reach external Teams meetings, since that was how the red team had been talking to it all along. A meeting chat offers a ready-made, two-way data channel. Message-size limits are a nuisance, but chopping data into chunks and encoding them is not hard. Best of all, the payload already ran inside Teams. Team-based chat tools have supplanted even office telephony in many firms; each convenience, the episode suggests, is also a hole poked in someone’s security layers. Virtual browsing may stop a lazy intruder. A patient one will simply hold the meeting inside the walls.

