Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Coding Tests Impersonate Recruiters to Infect Software Developers
September 1, 2026
Critical Langflow RCE (CVE-2024-34200) Actively Exploited by Attackers
September 1, 2026
Five Hackers Plead Guilty to ATM Jackpotting Attacks
September 1, 2026
Home/CyberSecurity News/Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users
CyberSecurity News

Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users

Key Takeaways A new social engineering campaign, “Spring Ring,” leverages Microsoft Teams’ external communication features to impersonate IT support. Attackers initiate chats and...

Marcus Rodriguez
Marcus Rodriguez
September 1, 2026 6 Min Read
3 0

Key Takeaways

  • A new social engineering campaign, “Spring Ring,” leverages Microsoft Teams’ external communication features to impersonate IT support.
  • Attackers initiate chats and then voice calls, attempting to persuade employees to grant remote access or execute malicious software.
  • The campaign, active from January to April 2026, targeted over 150 employees across at least 10 organizations.
  • This threat exploits human trust rather than a technical vulnerability in Teams, highlighting the need for robust user education.
  • Successful attacks can lead to malware deployment and attempts at lateral movement, even aiming for domain controller compromise.

Hackers Weaponize Microsoft Teams Help Desk Calls

Cybersecurity analysts have identified a sophisticated social engineering campaign, dubbed “Spring Ring,” where malicious actors are exploiting Microsoft Teams’ communication functionalities to impersonate internal IT support. This tactic allows them to establish a foothold for malware deployment and subsequent network compromise. The campaign, which operated between January and April 2026, engaged with more than 150 employees across at least 10 distinct organizations, according to findings.

Table Of Content

  • Key Takeaways
  • Hackers Weaponize Microsoft Teams Help Desk Calls
  • Initial Engagement and Deception
  • Attack Chain: From Remote Access to Domain Control
  • What You Should Do
  • Indicators of Compromise (IoCs)

The primary danger of the “Spring Ring” operation lies in its exploitation of human psychology. By mimicking familiar IT help desk personnel and engaging in live conversations, attackers can imbue their unexpected requests with a sense of urgency and legitimacy, bypassing typical skepticism associated with written phishing attempts.

Analysts at Unit 42 detected this activity after observing suspicious chat creations across numerous Microsoft 365 tenants. Their investigation uncovered 26 unique attacker identities involved in the scheme. Palo Alto Networks said in a report shared with Cyber Security News (CSN) that the campaign did not exploit a flaw within Microsoft Teams itself. Instead, it ingeniously abused the platform’s external communication capabilities and the inherent trust users place in their workplace collaboration tools.

This campaign underscores the critical importance of treating Teams impersonation with the same rigor as email phishing. The interactive nature of a voice call allows attackers to adapt their narrative, coercing victims into installing remote support tools or executing malicious files. This can rapidly escalate from a single compromised workstation to a broader network intrusion.

Initial Engagement and Deception

The “Spring Ring” campaign typically commenced with a one-on-one chat initiated via Teams from attacker-controlled .onmicrosoft.com tenants. These accounts were meticulously crafted with authoritative display names such as “help desk,” “IT assistance,” or “support staff.” Some even adopted the names of legitimate employees to enhance their credibility.

Following the initial chat request, the operators would place unsolicited voice calls, often leaving voicemails and persistently attempting to reach various targets. Successful conversations frequently extended for 10 to 15 minutes, providing ample time for the caller to guide an unsuspecting employee through steps that would likely raise red flags if communicated through text.

Attack Chain: From Remote Access to Domain Control

In what researchers categorized as “Campaign A,” the fraudulent technician would convince victims to either launch Microsoft Quick Assist or download legitimate remote monitoring and management (RMM) software. Upon gaining remote control, the intruder would assess the compromised host and domain environment. Subsequently, they used PowerShell to retrieve an obfuscated remote-access trojan (RAT) from their command-and-control infrastructure. This method bears a striking resemblance to a recent Microsoft Teams phishing campaign that also leveraged fake support staff to distribute malware. This reinforces the fundamental cybersecurity principle: employees must independently verify any unexpected support requests through established company contacts, never relying solely on the caller’s instructions.

“Campaign B” employed a more targeted approach, utilizing a bespoke cloud-hosted executable. This malicious program’s filename was tailored to include the specific target company and employee name. The executable would then copy itself into the Temp directory, establish persistence by creating `vhlp-*.exe` and `scnr-*.exe` components, and launch a hidden Microsoft Edge process that loaded a sideloaded extension.

The attackers then proceeded with lateral movement, using a Python executable (located at `C:ProgramDataIntegrityDatapython.exe`) to scan internal systems via SMB. This activity generated NTLM traffic directed toward the domain controller. The objective was to execute a PetitPotam attack, a technique designed to compel the domain controller to authenticate to an attacker-controlled machine, thereby allowing the attackers to relay that authentication for domain-level access. Although the attempted domain takeover was thwarted, this sequence clearly demonstrates how a seemingly innocuous help desk call can rapidly evolve into a severe identity-based attack. This pattern echoes previous Teams helpdesk impersonation scams that rely on external accounts and convincing support pretexts.

What You Should Do

  • Limit External Teams Chats: Restrict external communication within Teams to only essential business interactions.
  • Flag Suspicious Activity: Educate employees to recognize and report rapid transitions from chat to voice calls, especially from external or unexpected contacts.
  • Monitor for Unusual Software: Implement monitoring for unauthorized remote access tools, suspicious cloud downloads, and unusual SMB activity on endpoints.
  • Secure Domain Controllers: Pay close attention to authentication events involving domain controllers, particularly those related to NTLM relay attacks like PetitPotam.
  • Comprehensive User Education: Emphasize to employees that legitimate IT staff will never request the installation of unapproved software or demand immediate screen control during an unsolicited call.
  • Verify Out-of-Band: Instruct users to independently verify any unexpected support requests by contacting IT through a known, official channel, rather than using contact information provided by the caller.
  • Review Teams Audit Data: Regularly audit Teams activity for signs of external collaboration feature abuse, which can help detect early stages of such attacks.

Indicators of Compromise (IoCs)

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical JFrog Artifactory Auth Bypass CVE-2023-46233 Lets Attackers Gain Admin Access

Next Post

Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users
September 1, 2026
Critical JFrog Artifactory Auth Bypass CVE-2023-46233 Lets Attackers Gain Admin Access
September 1, 2026
21,000+ Microsoft Exchange Servers Exposed to Critical CVE-2026-62911 Exploits
September 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us
Type Indicator Description
Attacker identity helpcenter@ithelpcenter365[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@itprotectiondepartment[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@newsystemmaintenance[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@officedesk365[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@officesecures[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity helpdesk@tbcsschid[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity internal@internalusahelpdeskIT[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity it_assistance@teams0137[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity it@infrastructurefirewall[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity itassistant@bilelonellc[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@certifiednetworksec[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@internalsystemsdaily[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity ithelp@itprotectiondepartment[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity [email protected][.]com Generic help desk identity used in vishing attempts
Attacker identity ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity support@bilelonellc[.]onmicrosoft[.]com Generic help desk identity used in vishing attempts
Attacker identity andreas[..]@idigitalserviceoperation.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity andrew[..]@hapsinfrastructureops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity brandon[..]@devsitoperationhub.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity brian[..]@appssupportsys.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@adevpsitplatformops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@itplatformops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity clara[..]@systemsupportoperations.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity daniel[..]@opsnetsupportit.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity daniel[..]@apsitsupporthub.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity emily[..]@apsitechsupportdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity eric[..]@appopshelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity james[..]@helpitsupportcore.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity james[..]@itcoretechhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity jonathan[..]@itservicedesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity justin[..]@techopshelpsupp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity kevin[..]@itopsupportdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity kevin[..]@netopsdeskhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity leon[..]@netcorevdapp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity lucas[..]@applicationoperationsunit.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity martin[..]@syslanevdapp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity matthew[..]@supportopsupp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@appdeploymentservices.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@infratechopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity michael[..]@itopsdeskhelp.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity patrick[..]@infrastructureopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity rachel[..]@ioseccloudsupport.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity rebecca[..]@infrastructureopsservice.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity robert[..]@systemdeploymentcenter.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@apstechopsdeskdev.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@helpssupportcloudops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@secinfrahelpdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@apsscloudopsdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@helpitdevsupportops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity sarah[..]@itdevsupportops.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity scott[..]@cloudinfrastr.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity thomas[..]@networkoperationsec.onmicrosoft[.]com Partially redacted impersonated username
Attacker identity thomas[..]@seqapsitsupportops.onmicrosoft[.]com Partially redacted impersonated username
IP address 193.32.248[.]251 VPN or proxy infrastructure used in vishing attempts
IP address 193.138.7[.]142 VPN or proxy infrastructure used in vishing attempts
IP address 185.65.134[.]209 VPN or proxy infrastructure used in vishing attempts
IP address 178.130.47[.]46 VPN or proxy infrastructure used in vishing attempts
IP address 5.181.3[.]106 VPN or proxy infrastructure used in vishing attempts
IP address 2.56.172[.]214 VPN or proxy infrastructure used in vishing attempts
IP address 185.234.67[.]53 VPN or proxy infrastructure used in vishing attempts
IP address 45.8.157[.]185 VPN or proxy infrastructure used in vishing attempts
IP address 80.66.72[.]215 VPN or proxy infrastructure used in vishing attempts
IP address 136.0.20[.]6 VPN or proxy infrastructure used in vishing attempts
IP address 185.213.155[.]226 VPN or proxy infrastructure used in vishing attempts
IP address 185.155.99[.]161 VPN or proxy infrastructure used in vishing attempts
IP address 92.118.232[.]131 VPN or proxy infrastructure used in vishing attempts
IP address 45.182.189[.]80 VPN or proxy infrastructure used in vishing attempts
IP address 185.65.133[.]51 VPN or proxy infrastructure used in vishing attempts
IP address 45.33.22[.]47 VPN or proxy infrastructure used in vishing attempts
Domain san-sid[.]com Attacker-controlled domain hosting the PowerShell RAT payload
URL hxxps[:]//san-sid[.]com/owners URL hosting the obfuscated PowerShell RAT dropper
SHA-256 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b Obfuscated PowerShell payload
File name pattern <company_name>-org-filters-update-<victim_name>[.]exe Tailored Campaign B executable
File name pattern vhlp-*.exe Persistence-related executable copies observed in Campaign B
File name pattern scnr-*.exe Persistence-related executable copies observed in Campaign B