ThreatBeaconXThreatBeaconXSubscribe
HighThreat Intelligence · 16 min read · 7 views

Microsoft Teams Help Desk Impersonation Campaign Turns Employee Trust Into Enterprise Access

Threat actors are abusing Microsoft Teams external communication and voice calls to impersonate IT help-desk personnel and convince employees to provide remote access or execute malicious software. The campaign, tracked as Spring Ring, targeted more than 150 employees across at least 10 organizations between January and April 2026, with attackers using external Microsoft 365 tenants and convincing support-themed identities. The activity demonstrates how trusted collaboration platforms can be used as an initial-access mechanism without exploiting a software vulnerability. Once victims accepted remote assistance, attackers performed reconnaissance, deployed malware, used PowerShell, scanned internal systems over SMB, and attempted to move toward domain-level compromise.

Written by ThreatBeaconX Research Team·Published Sep 1, 2026

Description

A new social-engineering campaign is abusing Microsoft Teams help-desk calls to gain access to enterprise environments.

Tracked as Spring Ring, the operation uses attacker-controlled Microsoft 365 tenants and external Teams accounts that imitate legitimate IT support personnel. Attackers initiate one-to-one conversations with employees and subsequently place voice calls, creating a sense of urgency and legitimacy.

Security researchers identified 26 distinct attacker identities, with the campaign approaching more than 150 employees across at least 10 organizations. The activity was observed between January and April 2026.

Unlike a traditional Teams software vulnerability, the campaign primarily abuses legitimate external collaboration functionality combined with social engineering.

Technical Description

Attackers created external .onmicrosoft.com accounts using display names associated with help desks, IT support, or actual employees.

After initiating a Teams conversation, operators attempted to move the victim from text communication to a live voice call. Calls typically provided attackers with approximately 10–15 minutes to establish trust and convince employees to perform actions they would normally consider suspicious.

Two primary attack paths were identified.

Campaign A focused on obtaining remote access through tools such as Microsoft Quick Assist or remote-management software. After gaining access, attackers performed host and domain reconnaissance before using PowerShell to retrieve an obfuscated remote-access Trojan.

Campaign B involved a customized executable that incorporated the victim organization or employee name. The malware established persistence, launched a hidden Microsoft Edge process, and used a sideloaded extension as part of the attack chain.

Attack Overview

The observed attack chain can be summarized as:

External Teams Account → Fake IT Help Desk → Voice Call → Social Engineering → Remote Access → Malware Execution → Reconnaissance → Internal Network Discovery → Lateral Movement Attempt

The second campaign demonstrated how quickly an apparently harmless support call could develop into an enterprise-level identity and network attack. Attackers used Python-based scanning against internal systems over SMB and generated NTLM authentication traffic toward a domain controller.

They also attempted PetitPotam, with the objective of forcing authentication from the domain controller toward attacker-controlled infrastructure and potentially relaying the resulting authentication. The attempted domain takeover was blocked.

Technical Analysis

External Teams Impersonation

The attackers relied on external Teams communication rather than exploiting a vulnerability in Microsoft Teams.

Support-themed identities made the interaction appear legitimate, while live voice calls allowed attackers to respond dynamically to questions and overcome user hesitation.

Remote Access

In one attack path, victims were persuaded to launch Quick Assist or install remote-management software.

Once remote access was established, attackers could interact directly with the victim workstation and conduct reconnaissance.

PowerShell-Based Payload Retrieval

Attackers used PowerShell to retrieve an obfuscated remote-access Trojan from attacker-controlled infrastructure.

This allowed the threat actors to move from social engineering into malware deployment while using a legitimate Windows administration utility.

Internal Network Reconnaissance

In another attack path, attackers deployed a customized executable and subsequently used Python to scan internal systems over SMB.

The activity generated NTLM authentication traffic toward domain controllers, indicating an attempt to progress from workstation compromise toward credential relay and broader network access.

Domain-Level Attack Attempt

The attackers attempted PetitPotam to induce authentication from a domain controller to an attacker-controlled system.

Although the observed domain takeover attempt was unsuccessful, the technique demonstrates that the attackers were attempting to escalate the intrusion beyond the initially compromised workstation.

IOC

Type Indicator Description
Attacker identity helpcenter@ithelpcenter365[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@itprotectiondepartment[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@newsystemmaintenance[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@officedesk365[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@officesecures[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@tbcsschid[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity internal@internalusahelpdeskIT[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity it_assistance@teams0137[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity it@infrastructurefirewall[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity itassistant@bilelonellc[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@certifiednetworksec[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@internalsystemsdaily[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@itprotectiondepartment[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@mandatorynetworkmonitoring.onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity support@bilelonellc[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity andreas[..]@idigitalserviceoperation.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity andrew[..]@hapsinfrastructureops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity brandon[..]@devsitoperationhub.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity brian[..]@appssupportsys.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@adevpsitplatformops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@itplatformops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity clara[..]@systemsupportoperations.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity daniel[..]@opsnetsupportit.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity daniel[..]@apsitsupporthub.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity emily[..]@apsitechsupportdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity eric[..]@appopshelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity james[..]@helpitsupportcore.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity james[..]@itcoretechhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity jonathan[..]@itservicedesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity justin[..]@techopshelpsupp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity kevin[..]@itopsupportdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity kevin[..]@netopsdeskhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity leon[..]@netcorevdapp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity lucas[..]@applicationoperationsunit.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity martin[..]@syslanevdapp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity matthew[..]@supportopsupp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@appdeploymentservices.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@infratechopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@itopsdeskhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity patrick[..]@infrastructureopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity rachel[..]@ioseccloudsupport.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity rebecca[..]@infrastructureopsservice.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity robert[..]@systemdeploymentcenter.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@apstechopsdeskdev.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@helpssupportcloudops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@secinfrahelpdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@apsscloudopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@helpitdevsupportops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@itdevsupportops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity scott[..]@cloudinfrastr.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity thomas[..]@networkoperationsec.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity thomas[..]@seqapsitsupportops.onmicrosoft[.]com Partially redacted impersonated username
IP address 193.32.248[.]251 VPN or proxy infrastructure used in vishing attempts
IP address 193.138.7[.]142 VPN or proxy infrastructure used in vishing attempts
IP address 185.65.134[.]209 VPN or proxy infrastructure used in vishing attempts
IP address 178.130.47[.]46 VPN or proxy infrastructure used in vishing attempts
IP address 5.181.3[.]106 VPN or proxy infrastructure used in vishing attempts
IP address 2.56.172[.]214 VPN or proxy infrastructure used in vishing attempts
IP address 185.234.67[.]53 VPN or proxy infrastructure used in vishing attempts
IP address 45.8.157[.]185 VPN or proxy infrastructure used in vishing attempts
IP address 80.66.72[.]215 VPN or proxy infrastructure used in vishing attempts
IP address 136.0.20[.]6 VPN or proxy infrastructure used in vishing attempts
IP address 185.213.155[.]226 VPN or proxy infrastructure used in vishing attempts
IP address 185.155.99[.]161 VPN or proxy infrastructure used in vishing attempts
IP address 92.118.232[.]131 VPN or proxy infrastructure used in vishing attempts
IP address 45.182.189[.]80 VPN or proxy infrastructure used in vishing attempts
IP address 185.65.133[.]51 VPN or proxy infrastructure used in vishing attempts
IP address 45.33.22[.]47 VPN or proxy infrastructure used in vishing attempts
Domain san-sid[.]com Attacker-controlled domain hosting the PowerShell RAT payload
URL hxxps[:]//san-sid[.]com/owners URL hosting the obfuscated PowerShell RAT dropper
SHA-256 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b Obfuscated PowerShell payload
File name pattern <company_name>-org-filters-update-<victim_name>[.]exe Tailored Campaign B executable
File name pattern vhlp-*.exe Persistence-related executable copies observed in Campaign B
File name pattern scnr-*.exe Persistence-related executable copies observed in Campaign B
File path C:\ProgramData\IntegrityData\python.exe Python executable used for lateral movement activity

Potential Impact

Successful execution of this attack chain could result in:

  • Unauthorized remote access to employee systems
  • Malware deployment
  • Credential theft
  • Internal network reconnaissance
  • SMB-based network discovery
  • NTLM authentication exposure
  • Lateral movement
  • Domain-controller targeting
  • Potential enterprise-wide compromise
  • Data theft and ransomware deployment

The primary risk comes from combining social engineering with legitimate enterprise collaboration and remote-support functionality.

Recommendations

Immediate Actions

  1. Verify unsolicited Teams support requests through an independent communication channel.
  2. Do not provide remote control or screen-sharing access following unexpected calls.
  3. Prevent employees from installing unauthorized RMM or remote-support tools.
  4. Review Teams audit logs for suspicious external conversations and calls.
  5. Investigate unexpected launches of Quick Assist, RMM software, or remote-access utilities.
  6. Hunt for suspicious PowerShell execution following Teams interactions.
  7. Review SMB activity and unusual authentication attempts involving domain controllers.
  8. Investigate systems showing signs of unexpected internal network scanning.

Preventive Actions

  1. Restrict external Teams communication where business requirements do not justify it.
  2. Implement policies requiring IT support requests to be independently verified.
  3. Monitor external .onmicrosoft.com accounts communicating with employees.
  4. Alert on rapid transitions from external Teams chat → voice call → remote-access-tool execution.
  5. Monitor Microsoft 365 audit events associated with external Teams communication.
  6. Apply strong controls around remote-support applications.
  7. Disable unnecessary remote-control functionality for external participants.
  8. Implement protections against NTLM relay and PetitPotam-style authentication coercion.
  9. Segment critical systems and domain controllers from ordinary user networks.
  10. Conduct targeted awareness training around Teams-based help-desk impersonation.

Conclusion

The Spring Ring campaign demonstrates how attackers can transform a trusted collaboration platform into an effective initial-access channel without exploiting a software vulnerability. By combining convincing IT-support impersonation with Teams voice calls, remote-access tools, PowerShell, internal reconnaissance, and authentication-coercion techniques, attackers can progress from a single employee interaction toward broader enterprise compromise.

Organizations should therefore treat Teams-based social engineering with the same level of scrutiny as email phishing, particularly when an external user requests remote access, software installation, credential information, or other security-sensitive actions.

MITRE ATT&CK Mapping

T1566 — PhishingT1566.004 — Spearphishing VoiceT1204 — User ExecutionT1219 — Remote Access SoftwareT1059.001 — PowerShellT1046 — Network Service ScanningT1021.002 — SMB/Windows Admin SharesT1557.001 — LLMNR/NBT-NS Poisoning and SMB RelayT1484.001 — Domain or Tenant Policy Modification