But the attack relied on the target using the browser version
The relevant part is:
* they scheduled a meeting with me to connect. the meeting was on ms teams. the meeting had what seemed to be a group of people that were involved.
* the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT.