If I'd write malware, I'd drop it into
\AppData\Local\Microsoft\TeamsMeetingAddin\
- user has write access
- probably excluded from some detections
- SOC analyst: 'ah, just another MS Teams quirk. we've seen so many.'
- availability has top priority ;)