Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution.

The activity ran from January through April 2026 and approached more than 150 employees at at least 10 organizations.

Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate.

Analysts at Unit 42 identified the operation after detecting suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities.

Palo Alto Networks said in a report shared with Cyber Security News (CSN) that the group did not exploit a flaw in Teams. Instead, it abused external communication features and the trust users place in workplace collaboration tools.

The campaign shows why Teams impersonation deserves the same scrutiny as email phishing. Attackers can adjust their story during a call, persuade a victim to run a remote support utility, and quickly move from a single workstation toward systems that control an entire network.

Hackers Weaponize Microsoft Teams Help Desk Calls

Spring Ring began with a one-to-one Teams chat from attacker-controlled .onmicrosoft.com tenants. The accounts carried authoritative display names such as help desk, IT assistance, or support staff, while some used names of real people to make the contact appear more credible.

After a chat request, the operator placed unsolicited voice calls, sometimes leaving voicemails and repeatedly trying different targets.

External chat created (Source – Unit42)

Successful conversations commonly lasted 10 to 15 minutes, giving the caller time to guide an employee through steps that would normally trigger suspicion in a written message.

In Campaign A, the fake technician persuaded victims to launch Quick Assist or download remote monitoring and management software.

Once remote control was granted, the intruder checked the host and domain, then used PowerShell to retrieve an obfuscated remote-access trojan from its infrastructure.

That method closely echoes a recent Microsoft Teams phishing campaign in which fake support staff pushed malware through the collaboration service.

It also reinforces a basic rule: employees should independently verify an unexpected support request using a known company contact, never the caller’s instructions.

From Remote Access to Domain Control

Campaign B used a tailored cloud-hosted executable whose name included the target company and employee.

The program copied itself into the Temp directory, created vhlp-.exe and scnr-.exe components for persistence, and launched a hidden Microsoft Edge process that loaded a sideloaded extension.

The attackers then used Python to scan internal systems over SMB and generate NTLM traffic toward the domain controller.

They attempted PetitPotam, a technique intended to force the controller to authenticate to an attacker-controlled machine, where that authentication could be relayed for domain-level access.

Full attack flow of the two Spring Ring campaigns (Source – Unit42)

The attempted takeover was blocked, but the sequence illustrates how a help desk call can become a serious identity attack. Readers following Teams helpdesk impersonation scams will recognize the same reliance on external accounts and a convincing support pretext.

Organizations should limit external Teams chats to genuine business needs, flag a rapid chat-to-call shift, and investigate unusual remote-tool launches, cloud downloads, and SMB activity.

Security teams should also watch authentication events involving domain controllers, an issue explained in coverage of MITM6 and NTLM relay.

User education must be specific: IT staff should never ask workers to install unapproved tools or grant screen control after an unsolicited call.

Combining that policy with behavioral monitoring and review of Teams audit data can catch the chain early, as outlined in reporting on external collaboration feature abuse.

The trusted communication platforms are now being used as a route to domain-level exploitation. The immediate defense is simple: stop, verify the request out of band, and report the external account before any tool is opened.

That approach reduces the chance that an attacker can turn a routine Teams exchange into a costly enterprise-wide incident overnight.

Indicators of compromise (IoCs):-

Type Indicator Description
Attacker identity helpcenter@ithelpcenter365[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@itprotectiondepartment[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@newsystemmaintenance[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@officedesk365[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@officesecures[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@tbcsschid[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity internal@internalusahelpdeskIT[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity it_assistance@teams0137[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity it@infrastructurefirewall[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity itassistant@bilelonellc[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@certifiednetworksec[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@internalsystemsdaily[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@itprotectiondepartment[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity [email protected][.]com Generic help desk identity used in vishing attempts
Attacker identity ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity support@bilelonellc[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity andreas[..]@idigitalserviceoperation.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity andrew[..]@hapsinfrastructureops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity brandon[..]@devsitoperationhub.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity brian[..]@appssupportsys.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@adevpsitplatformops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@itplatformops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity clara[..]@systemsupportoperations.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity daniel[..]@opsnetsupportit.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity daniel[..]@apsitsupporthub.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity emily[..]@apsitechsupportdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity eric[..]@appopshelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity james[..]@helpitsupportcore.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity james[..]@itcoretechhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity jonathan[..]@itservicedesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity justin[..]@techopshelpsupp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity kevin[..]@itopsupportdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity kevin[..]@netopsdeskhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity leon[..]@netcorevdapp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity lucas[..]@applicationoperationsunit.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity martin[..]@syslanevdapp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity matthew[..]@supportopsupp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@appdeploymentservices.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@infratechopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@itopsdeskhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity patrick[..]@infrastructureopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity rachel[..]@ioseccloudsupport.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity rebecca[..]@infrastructureopsservice.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity robert[..]@systemdeploymentcenter.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@apstechopsdeskdev.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@helpssupportcloudops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@secinfrahelpdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@apsscloudopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@helpitdevsupportops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@itdevsupportops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity scott[..]@cloudinfrastr.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity thomas[..]@networkoperationsec.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity thomas[..]@seqapsitsupportops.onmicrosoft[.]com Partially redacted impersonated username
IP address 193.32.248[.]251 VPN or proxy infrastructure used in vishing attempts
IP address 193.138.7[.]142 VPN or proxy infrastructure used in vishing attempts
IP address 185.65.134[.]209 VPN or proxy infrastructure used in vishing attempts
IP address 178.130.47[.]46 VPN or proxy infrastructure used in vishing attempts
IP address 5.181.3[.]106 VPN or proxy infrastructure used in vishing attempts
IP address 2.56.172[.]214 VPN or proxy infrastructure used in vishing attempts
IP address 185.234.67[.]53 VPN or proxy infrastructure used in vishing attempts
IP address 45.8.157[.]185 VPN or proxy infrastructure used in vishing attempts
IP address 80.66.72[.]215 VPN or proxy infrastructure used in vishing attempts
IP address 136.0.20[.]6 VPN or proxy infrastructure used in vishing attempts
IP address 185.213.155[.]226 VPN or proxy infrastructure used in vishing attempts
IP address 185.155.99[.]161 VPN or proxy infrastructure used in vishing attempts
IP address 92.118.232[.]131 VPN or proxy infrastructure used in vishing attempts
IP address 45.182.189[.]80 VPN or proxy infrastructure used in vishing attempts
IP address 185.65.133[.]51 VPN or proxy infrastructure used in vishing attempts
IP address 45.33.22[.]47 VPN or proxy infrastructure used in vishing attempts
Domain san-sid[.]com Attacker-controlled domain hosting the PowerShell RAT payload
URL hxxps[:]//san-sid[.]com/owners URL hosting the obfuscated PowerShell RAT dropper
SHA-256 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b Obfuscated PowerShell payload
File name pattern <company_name>-org-filters-update-<victim_name>[.]exe Tailored Campaign B executable
File name pattern vhlp-*.exe Persistence-related executable copies observed in Campaign B
File name pattern scnr-*.exe Persistence-related executable copies observed in Campaign B
File path C:ProgramDataIntegrityDatapython.exe Python executable used for lateral movement activity

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement appeared first on Cyber Security News.