Cyber Security News

Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement

Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution.

The activity ran from January through April 2026 and approached more than 150 employees at at least 10 organizations.

Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate.

Analysts at Unit 42 identified the operation after detecting suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities.

Palo Alto Networks said in a report shared with Cyber Security News (CSN) that the group did not exploit a flaw in Teams. Instead, it abused external communication features and the trust users place in workplace collaboration tools.

The campaign shows why Teams impersonation deserves the same scrutiny as email phishing. Attackers can adjust their story during a call, persuade a victim to run a remote support utility, and quickly move from a single workstation toward systems that control an entire network.

Hackers Weaponize Microsoft Teams Help Desk Calls

Spring Ring began with a one-to-one Teams chat from attacker-controlled .onmicrosoft.com tenants. The accounts carried authoritative display names such as help desk, IT assistance, or support staff, while some used names of real people to make the contact appear more credible.

After a chat request, the operator placed unsolicited voice calls, sometimes leaving voicemails and repeatedly trying different targets.

External chat created (Source – Unit42)

Successful conversations commonly lasted 10 to 15 minutes, giving the caller time to guide an employee through steps that would normally trigger suspicion in a written message.

In Campaign A, the fake technician persuaded victims to launch Quick Assist or download remote monitoring and management software.

Once remote control was granted, the intruder checked the host and domain, then used PowerShell to retrieve an obfuscated remote-access trojan from its infrastructure.

That method closely echoes a recent Microsoft Teams phishing campaign in which fake support staff pushed malware through the collaboration service.

It also reinforces a basic rule: employees should independently verify an unexpected support request using a known company contact, never the caller’s instructions.

From Remote Access to Domain Control

Campaign B used a tailored cloud-hosted executable whose name included the target company and employee.

The program copied itself into the Temp directory, created vhlp-.exe and scnr-.exe components for persistence, and launched a hidden Microsoft Edge process that loaded a sideloaded extension.

The attackers then used Python to scan internal systems over SMB and generate NTLM traffic toward the domain controller.

They attempted PetitPotam, a technique intended to force the controller to authenticate to an attacker-controlled machine, where that authentication could be relayed for domain-level access.

Full attack flow of the two Spring Ring campaigns (Source – Unit42)

The attempted takeover was blocked, but the sequence illustrates how a help desk call can become a serious identity attack. Readers following Teams helpdesk impersonation scams will recognize the same reliance on external accounts and a convincing support pretext.

Organizations should limit external Teams chats to genuine business needs, flag a rapid chat-to-call shift, and investigate unusual remote-tool launches, cloud downloads, and SMB activity.

Security teams should also watch authentication events involving domain controllers, an issue explained in coverage of MITM6 and NTLM relay.

User education must be specific: IT staff should never ask workers to install unapproved tools or grant screen control after an unsolicited call.

Combining that policy with behavioral monitoring and review of Teams audit data can catch the chain early, as outlined in reporting on external collaboration feature abuse.

The trusted communication platforms are now being used as a route to domain-level exploitation. The immediate defense is simple: stop, verify the request out of band, and report the external account before any tool is opened.

That approach reduces the chance that an attacker can turn a routine Teams exchange into a costly enterprise-wide incident overnight.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Attacker identityhelpcenter@ithelpcenter365[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityhelpdesk@itprotectiondepartment[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityhelpdesk@newsystemmaintenance[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityhelpdesk@officedesk365[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityhelpdesk@officesecures[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityhelpdesk@tbcsschid[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityinternal@internalusahelpdeskIT[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityit_assistance@teams0137[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityit@infrastructurefirewall[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityitadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityitassistant@bilelonellc[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityithelp@certifiednetworksec[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityithelp@internalsystemsdaily[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityithelp@itprotectiondepartment[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityithelp@mandatorynetworkmonitoring.onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identitysupport@bilelonellc[.]onmicrosoft[.]comGeneric help desk identity used in vishing attempts
Attacker identityandreas[..]@idigitalserviceoperation.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityandrew[..]@hapsinfrastructureops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitybrandon[..]@devsitoperationhub.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitybrian[..]@appssupportsys.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitychristopher[..]@adevpsitplatformops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitychristopher[..]@itplatformops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitychristopher[..]@helpaphelpitinfraops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityclara[..]@systemsupportoperations.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitydaniel[..]@opsnetsupportit.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitydaniel[..]@apsitsupporthub.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityemily[..]@apsitechsupportdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityeric[..]@appopshelp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityhenrik[..]@enterpriseoperationsflo.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityjames[..]@helpitsupportcore.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityjames[..]@itcoretechhelp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityjonathan[..]@itservicedesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityjustin[..]@techopshelpsupp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitykevin[..]@itopsupportdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitykevin[..]@netopsdeskhelp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityleon[..]@netcorevdapp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitylucas[..]@applicationoperationsunit.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitymartin[..]@syslanevdapp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitymatthew[..]@supportopsupp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitymichael[..]@appdeploymentservices.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitymichael[..]@infratechopsdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitymichael[..]@itopsdeskhelp.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitypatrick[..]@infrastructureopsdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityrachel[..]@ioseccloudsupport.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityrebecca[..]@infrastructureopsservice.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityrobert[..]@systemdeploymentcenter.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityryan[..]@apstechopsdeskdev.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityryan[..]@helpssupportcloudops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityryan[..]@seqhelpitsuppnetops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitysarah[..]@secinfrahelpdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitysarah[..]@apsscloudopsdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitysarah[..]@helpitdevsupportops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitysarah[..]@itdevsupportops.onmicrosoft[.]comPartially redacted impersonated username
Attacker identityscott[..]@cloudinfrastr.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitysteven[..]@ittechnologyopsitdesk.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitythomas[..]@networkoperationsec.onmicrosoft[.]comPartially redacted impersonated username
Attacker identitythomas[..]@seqapsitsupportops.onmicrosoft[.]comPartially redacted impersonated username
IP address193.32.248[.]251VPN or proxy infrastructure used in vishing attempts
IP address193.138.7[.]142VPN or proxy infrastructure used in vishing attempts
IP address185.65.134[.]209VPN or proxy infrastructure used in vishing attempts
IP address178.130.47[.]46VPN or proxy infrastructure used in vishing attempts
IP address5.181.3[.]106VPN or proxy infrastructure used in vishing attempts
IP address2.56.172[.]214VPN or proxy infrastructure used in vishing attempts
IP address185.234.67[.]53VPN or proxy infrastructure used in vishing attempts
IP address45.8.157[.]185VPN or proxy infrastructure used in vishing attempts
IP address80.66.72[.]215VPN or proxy infrastructure used in vishing attempts
IP address136.0.20[.]6VPN or proxy infrastructure used in vishing attempts
IP address185.213.155[.]226VPN or proxy infrastructure used in vishing attempts
IP address185.155.99[.]161VPN or proxy infrastructure used in vishing attempts
IP address92.118.232[.]131VPN or proxy infrastructure used in vishing attempts
IP address45.182.189[.]80VPN or proxy infrastructure used in vishing attempts
IP address185.65.133[.]51VPN or proxy infrastructure used in vishing attempts
IP address45.33.22[.]47VPN or proxy infrastructure used in vishing attempts
Domainsan-sid[.]comAttacker-controlled domain hosting the PowerShell RAT payload
URLhxxps[:]//san-sid[.]com/ownersURL hosting the obfuscated PowerShell RAT dropper
SHA-25624ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5bObfuscated PowerShell payload
File name pattern<company_name>-org-filters-update-<victim_name>[.]exeTailored Campaign B executable
File name patternvhlp-*.exePersistence-related executable copies observed in Campaign B
File name patternscnr-*.exePersistence-related executable copies observed in Campaign B
File pathC:\ProgramData\IntegrityData\python.exePython executable used for lateral movement activity

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago