Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution.
The activity ran from January through April 2026 and approached more than 150 employees at at least 10 organizations.
Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate.
Analysts at Unit 42 identified the operation after detecting suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities.
Palo Alto Networks said in a report shared with Cyber Security News (CSN) that the group did not exploit a flaw in Teams. Instead, it abused external communication features and the trust users place in workplace collaboration tools.
The campaign shows why Teams impersonation deserves the same scrutiny as email phishing. Attackers can adjust their story during a call, persuade a victim to run a remote support utility, and quickly move from a single workstation toward systems that control an entire network.
Hackers Weaponize Microsoft Teams Help Desk Calls
Spring Ring began with a one-to-one Teams chat from attacker-controlled .onmicrosoft.com tenants. The accounts carried authoritative display names such as help desk, IT assistance, or support staff, while some used names of real people to make the contact appear more credible.
After a chat request, the operator placed unsolicited voice calls, sometimes leaving voicemails and repeatedly trying different targets.

Successful conversations commonly lasted 10 to 15 minutes, giving the caller time to guide an employee through steps that would normally trigger suspicion in a written message.
In Campaign A, the fake technician persuaded victims to launch Quick Assist or download remote monitoring and management software.
Once remote control was granted, the intruder checked the host and domain, then used PowerShell to retrieve an obfuscated remote-access trojan from its infrastructure.
That method closely echoes a recent Microsoft Teams phishing campaign in which fake support staff pushed malware through the collaboration service.
It also reinforces a basic rule: employees should independently verify an unexpected support request using a known company contact, never the caller’s instructions.
From Remote Access to Domain Control
Campaign B used a tailored cloud-hosted executable whose name included the target company and employee.
The program copied itself into the Temp directory, created vhlp-.exe and scnr-.exe components for persistence, and launched a hidden Microsoft Edge process that loaded a sideloaded extension.
The attackers then used Python to scan internal systems over SMB and generate NTLM traffic toward the domain controller.
They attempted PetitPotam, a technique intended to force the controller to authenticate to an attacker-controlled machine, where that authentication could be relayed for domain-level access.

The attempted takeover was blocked, but the sequence illustrates how a help desk call can become a serious identity attack. Readers following Teams helpdesk impersonation scams will recognize the same reliance on external accounts and a convincing support pretext.
Organizations should limit external Teams chats to genuine business needs, flag a rapid chat-to-call shift, and investigate unusual remote-tool launches, cloud downloads, and SMB activity.
Security teams should also watch authentication events involving domain controllers, an issue explained in coverage of MITM6 and NTLM relay.
User education must be specific: IT staff should never ask workers to install unapproved tools or grant screen control after an unsolicited call.
Combining that policy with behavioral monitoring and review of Teams audit data can catch the chain early, as outlined in reporting on external collaboration feature abuse.
The trusted communication platforms are now being used as a route to domain-level exploitation. The immediate defense is simple: stop, verify the request out of band, and report the external account before any tool is opened.
That approach reduces the chance that an attacker can turn a routine Teams exchange into a costly enterprise-wide incident overnight.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Attacker identity | helpcenter@ithelpcenter365[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@itprotectiondepartment[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@newsystemmaintenance[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@officedesk365[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@officesecures[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@tbcsschid[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | internal@internalusahelpdeskIT[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | it_assistance@teams0137[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | it@infrastructurefirewall[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | itassistant@bilelonellc[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@certifiednetworksec[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@internalsystemsdaily[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@itprotectiondepartment[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | [email protected][.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | support@bilelonellc[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | andreas[..]@idigitalserviceoperation.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | andrew[..]@hapsinfrastructureops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | brandon[..]@devsitoperationhub.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | brian[..]@appssupportsys.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | christopher[..]@adevpsitplatformops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | christopher[..]@itplatformops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | clara[..]@systemsupportoperations.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | daniel[..]@opsnetsupportit.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | daniel[..]@apsitsupporthub.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | emily[..]@apsitechsupportdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | eric[..]@appopshelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | james[..]@helpitsupportcore.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | james[..]@itcoretechhelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | jonathan[..]@itservicedesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | justin[..]@techopshelpsupp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | kevin[..]@itopsupportdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | kevin[..]@netopsdeskhelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | leon[..]@netcorevdapp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | lucas[..]@applicationoperationsunit.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | martin[..]@syslanevdapp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | matthew[..]@supportopsupp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | michael[..]@appdeploymentservices.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | michael[..]@infratechopsdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | michael[..]@itopsdeskhelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | patrick[..]@infrastructureopsdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | rachel[..]@ioseccloudsupport.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | rebecca[..]@infrastructureopsservice.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | robert[..]@systemdeploymentcenter.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | ryan[..]@apstechopsdeskdev.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | ryan[..]@helpssupportcloudops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@secinfrahelpdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@apsscloudopsdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@helpitdevsupportops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@itdevsupportops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | scott[..]@cloudinfrastr.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | thomas[..]@networkoperationsec.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | thomas[..]@seqapsitsupportops.onmicrosoft[.]com |
Partially redacted impersonated username |
| IP address | 193.32.248[.]251 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 193.138.7[.]142 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.65.134[.]209 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 178.130.47[.]46 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 5.181.3[.]106 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 2.56.172[.]214 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.234.67[.]53 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.8.157[.]185 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 80.66.72[.]215 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 136.0.20[.]6 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.213.155[.]226 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.155.99[.]161 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 92.118.232[.]131 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.182.189[.]80 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.65.133[.]51 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.33.22[.]47 |
VPN or proxy infrastructure used in vishing attempts |
| Domain | san-sid[.]com |
Attacker-controlled domain hosting the PowerShell RAT payload |
| URL | hxxps[:]//san-sid[.]com/owners |
URL hosting the obfuscated PowerShell RAT dropper |
| SHA-256 | 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b |
Obfuscated PowerShell payload |
| File name pattern | <company_name>-org-filters-update-<victim_name>[.]exe |
Tailored Campaign B executable |
| File name pattern | vhlp-*.exe |
Persistence-related executable copies observed in Campaign B |
| File name pattern | scnr-*.exe |
Persistence-related executable copies observed in Campaign B |
| File path | C:ProgramDataIntegrityDatapython.exe |
Python executable used for lateral movement activity |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement appeared first on Cyber Security News.
