Description
A new social-engineering campaign is abusing Microsoft Teams help-desk calls to gain access to enterprise environments.
Tracked as Spring Ring, the operation uses attacker-controlled Microsoft 365 tenants and external Teams accounts that imitate legitimate IT support personnel. Attackers initiate one-to-one conversations with employees and subsequently place voice calls, creating a sense of urgency and legitimacy.
Security researchers identified 26 distinct attacker identities, with the campaign approaching more than 150 employees across at least 10 organizations. The activity was observed between January and April 2026.
Unlike a traditional Teams software vulnerability, the campaign primarily abuses legitimate external collaboration functionality combined with social engineering.
Technical Description
Attackers created external .onmicrosoft.com accounts using display names associated with help desks, IT support, or actual employees.
After initiating a Teams conversation, operators attempted to move the victim from text communication to a live voice call. Calls typically provided attackers with approximately 10–15 minutes to establish trust and convince employees to perform actions they would normally consider suspicious.
Two primary attack paths were identified.
Campaign A focused on obtaining remote access through tools such as Microsoft Quick Assist or remote-management software. After gaining access, attackers performed host and domain reconnaissance before using PowerShell to retrieve an obfuscated remote-access Trojan.
Campaign B involved a customized executable that incorporated the victim organization or employee name. The malware established persistence, launched a hidden Microsoft Edge process, and used a sideloaded extension as part of the attack chain.
Attack Overview
The observed attack chain can be summarized as:
External Teams Account → Fake IT Help Desk → Voice Call → Social Engineering → Remote Access → Malware Execution → Reconnaissance → Internal Network Discovery → Lateral Movement Attempt
The second campaign demonstrated how quickly an apparently harmless support call could develop into an enterprise-level identity and network attack. Attackers used Python-based scanning against internal systems over SMB and generated NTLM authentication traffic toward a domain controller.
They also attempted PetitPotam, with the objective of forcing authentication from the domain controller toward attacker-controlled infrastructure and potentially relaying the resulting authentication. The attempted domain takeover was blocked.
Technical Analysis
External Teams Impersonation
The attackers relied on external Teams communication rather than exploiting a vulnerability in Microsoft Teams.
Support-themed identities made the interaction appear legitimate, while live voice calls allowed attackers to respond dynamically to questions and overcome user hesitation.
Remote Access
In one attack path, victims were persuaded to launch Quick Assist or install remote-management software.
Once remote access was established, attackers could interact directly with the victim workstation and conduct reconnaissance.
PowerShell-Based Payload Retrieval
Attackers used PowerShell to retrieve an obfuscated remote-access Trojan from attacker-controlled infrastructure.
This allowed the threat actors to move from social engineering into malware deployment while using a legitimate Windows administration utility.
Internal Network Reconnaissance
In another attack path, attackers deployed a customized executable and subsequently used Python to scan internal systems over SMB.
The activity generated NTLM authentication traffic toward domain controllers, indicating an attempt to progress from workstation compromise toward credential relay and broader network access.
Domain-Level Attack Attempt
The attackers attempted PetitPotam to induce authentication from a domain controller to an attacker-controlled system.
Although the observed domain takeover attempt was unsuccessful, the technique demonstrates that the attackers were attempting to escalate the intrusion beyond the initially compromised workstation.
IOC
| Type | Indicator | Description |
| Attacker identity | helpcenter@ithelpcenter365[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@itprotectiondepartment[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@newsystemmaintenance[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@officedesk365[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@officesecures[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@tbcsschid[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | internal@internalusahelpdeskIT[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | it_assistance@teams0137[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | it@infrastructurefirewall[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | itassistant@bilelonellc[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@certifiednetworksec[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@internalsystemsdaily[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@itprotectiondepartment[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@mandatorynetworkmonitoring.onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | support@bilelonellc[.]onmicrosoft[.]com | Generic help desk identity used in vishing attempts |
| Attacker identity | andreas[..]@idigitalserviceoperation.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | andrew[..]@hapsinfrastructureops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | brandon[..]@devsitoperationhub.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | brian[..]@appssupportsys.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | christopher[..]@adevpsitplatformops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | christopher[..]@itplatformops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | clara[..]@systemsupportoperations.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | daniel[..]@opsnetsupportit.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | daniel[..]@apsitsupporthub.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | emily[..]@apsitechsupportdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | eric[..]@appopshelp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | james[..]@helpitsupportcore.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | james[..]@itcoretechhelp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | jonathan[..]@itservicedesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | justin[..]@techopshelpsupp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | kevin[..]@itopsupportdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | kevin[..]@netopsdeskhelp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | leon[..]@netcorevdapp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | lucas[..]@applicationoperationsunit.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | martin[..]@syslanevdapp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | matthew[..]@supportopsupp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | michael[..]@appdeploymentservices.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | michael[..]@infratechopsdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | michael[..]@itopsdeskhelp.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | patrick[..]@infrastructureopsdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | rachel[..]@ioseccloudsupport.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | rebecca[..]@infrastructureopsservice.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | robert[..]@systemdeploymentcenter.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | ryan[..]@apstechopsdeskdev.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | ryan[..]@helpssupportcloudops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | sarah[..]@secinfrahelpdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | sarah[..]@apsscloudopsdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | sarah[..]@helpitdevsupportops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | sarah[..]@itdevsupportops.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | scott[..]@cloudinfrastr.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | thomas[..]@networkoperationsec.onmicrosoft[.]com | Partially redacted impersonated username |
| Attacker identity | thomas[..]@seqapsitsupportops.onmicrosoft[.]com | Partially redacted impersonated username |
| IP address | 193.32.248[.]251 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 193.138.7[.]142 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.65.134[.]209 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 178.130.47[.]46 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 5.181.3[.]106 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 2.56.172[.]214 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.234.67[.]53 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.8.157[.]185 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 80.66.72[.]215 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 136.0.20[.]6 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.213.155[.]226 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.155.99[.]161 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 92.118.232[.]131 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.182.189[.]80 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.65.133[.]51 | VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.33.22[.]47 | VPN or proxy infrastructure used in vishing attempts |
| Domain | san-sid[.]com | Attacker-controlled domain hosting the PowerShell RAT payload |
| URL | hxxps[:]//san-sid[.]com/owners | URL hosting the obfuscated PowerShell RAT dropper |
| SHA-256 | 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b | Obfuscated PowerShell payload |
| File name pattern | <company_name>-org-filters-update-<victim_name>[.]exe | Tailored Campaign B executable |
| File name pattern | vhlp-*.exe | Persistence-related executable copies observed in Campaign B |
| File name pattern | scnr-*.exe | Persistence-related executable copies observed in Campaign B |
| File path | C:\ProgramData\IntegrityData\python.exe | Python executable used for lateral movement activity |
Potential Impact
Successful execution of this attack chain could result in:
- Unauthorized remote access to employee systems
- Malware deployment
- Credential theft
- Internal network reconnaissance
- SMB-based network discovery
- NTLM authentication exposure
- Lateral movement
- Domain-controller targeting
- Potential enterprise-wide compromise
- Data theft and ransomware deployment
The primary risk comes from combining social engineering with legitimate enterprise collaboration and remote-support functionality.
Recommendations
Immediate Actions
- Verify unsolicited Teams support requests through an independent communication channel.
- Do not provide remote control or screen-sharing access following unexpected calls.
- Prevent employees from installing unauthorized RMM or remote-support tools.
- Review Teams audit logs for suspicious external conversations and calls.
- Investigate unexpected launches of Quick Assist, RMM software, or remote-access utilities.
- Hunt for suspicious PowerShell execution following Teams interactions.
- Review SMB activity and unusual authentication attempts involving domain controllers.
- Investigate systems showing signs of unexpected internal network scanning.
Preventive Actions
- Restrict external Teams communication where business requirements do not justify it.
- Implement policies requiring IT support requests to be independently verified.
-
Monitor external
.onmicrosoft.comaccounts communicating with employees. - Alert on rapid transitions from external Teams chat → voice call → remote-access-tool execution.
- Monitor Microsoft 365 audit events associated with external Teams communication.
- Apply strong controls around remote-support applications.
- Disable unnecessary remote-control functionality for external participants.
- Implement protections against NTLM relay and PetitPotam-style authentication coercion.
- Segment critical systems and domain controllers from ordinary user networks.
- Conduct targeted awareness training around Teams-based help-desk impersonation.
Conclusion
The Spring Ring campaign demonstrates how attackers can transform a trusted collaboration platform into an effective initial-access channel without exploiting a software vulnerability. By combining convincing IT-support impersonation with Teams voice calls, remote-access tools, PowerShell, internal reconnaissance, and authentication-coercion techniques, attackers can progress from a single employee interaction toward broader enterprise compromise.
Organizations should therefore treat Teams-based social engineering with the same level of scrutiny as email phishing, particularly when an external user requests remote access, software installation, credential information, or other security-sensitive actions.