Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders ...