Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users
Key Takeaways A new social engineering campaign, “Spring Ring,” leverages Microsoft Teams’ external communication features to impersonate IT support. Attackers initiate chats and...
Key Takeaways
- A new social engineering campaign, “Spring Ring,” leverages Microsoft Teams’ external communication features to impersonate IT support.
- Attackers initiate chats and then voice calls, attempting to persuade employees to grant remote access or execute malicious software.
- The campaign, active from January to April 2026, targeted over 150 employees across at least 10 organizations.
- This threat exploits human trust rather than a technical vulnerability in Teams, highlighting the need for robust user education.
- Successful attacks can lead to malware deployment and attempts at lateral movement, even aiming for domain controller compromise.
Hackers Weaponize Microsoft Teams Help Desk Calls
Cybersecurity analysts have identified a sophisticated social engineering campaign, dubbed “Spring Ring,” where malicious actors are exploiting Microsoft Teams’ communication functionalities to impersonate internal IT support. This tactic allows them to establish a foothold for malware deployment and subsequent network compromise. The campaign, which operated between January and April 2026, engaged with more than 150 employees across at least 10 distinct organizations, according to findings.
Table Of Content
The primary danger of the “Spring Ring” operation lies in its exploitation of human psychology. By mimicking familiar IT help desk personnel and engaging in live conversations, attackers can imbue their unexpected requests with a sense of urgency and legitimacy, bypassing typical skepticism associated with written phishing attempts.
Analysts at Unit 42 detected this activity after observing suspicious chat creations across numerous Microsoft 365 tenants. Their investigation uncovered 26 unique attacker identities involved in the scheme. Palo Alto Networks said in a report shared with Cyber Security News (CSN) that the campaign did not exploit a flaw within Microsoft Teams itself. Instead, it ingeniously abused the platform’s external communication capabilities and the inherent trust users place in their workplace collaboration tools.
This campaign underscores the critical importance of treating Teams impersonation with the same rigor as email phishing. The interactive nature of a voice call allows attackers to adapt their narrative, coercing victims into installing remote support tools or executing malicious files. This can rapidly escalate from a single compromised workstation to a broader network intrusion.
Initial Engagement and Deception
The “Spring Ring” campaign typically commenced with a one-on-one chat initiated via Teams from attacker-controlled .onmicrosoft.com tenants. These accounts were meticulously crafted with authoritative display names such as “help desk,” “IT assistance,” or “support staff.” Some even adopted the names of legitimate employees to enhance their credibility.
Following the initial chat request, the operators would place unsolicited voice calls, often leaving voicemails and persistently attempting to reach various targets. Successful conversations frequently extended for 10 to 15 minutes, providing ample time for the caller to guide an unsuspecting employee through steps that would likely raise red flags if communicated through text.
Attack Chain: From Remote Access to Domain Control
In what researchers categorized as “Campaign A,” the fraudulent technician would convince victims to either launch Microsoft Quick Assist or download legitimate remote monitoring and management (RMM) software. Upon gaining remote control, the intruder would assess the compromised host and domain environment. Subsequently, they used PowerShell to retrieve an obfuscated remote-access trojan (RAT) from their command-and-control infrastructure. This method bears a striking resemblance to a recent Microsoft Teams phishing campaign that also leveraged fake support staff to distribute malware. This reinforces the fundamental cybersecurity principle: employees must independently verify any unexpected support requests through established company contacts, never relying solely on the caller’s instructions.
“Campaign B” employed a more targeted approach, utilizing a bespoke cloud-hosted executable. This malicious program’s filename was tailored to include the specific target company and employee name. The executable would then copy itself into the Temp directory, establish persistence by creating `vhlp-*.exe` and `scnr-*.exe` components, and launch a hidden Microsoft Edge process that loaded a sideloaded extension.
The attackers then proceeded with lateral movement, using a Python executable (located at `C:ProgramDataIntegrityDatapython.exe`) to scan internal systems via SMB. This activity generated NTLM traffic directed toward the domain controller. The objective was to execute a PetitPotam attack, a technique designed to compel the domain controller to authenticate to an attacker-controlled machine, thereby allowing the attackers to relay that authentication for domain-level access. Although the attempted domain takeover was thwarted, this sequence clearly demonstrates how a seemingly innocuous help desk call can rapidly evolve into a severe identity-based attack. This pattern echoes previous Teams helpdesk impersonation scams that rely on external accounts and convincing support pretexts.
What You Should Do
- Limit External Teams Chats: Restrict external communication within Teams to only essential business interactions.
- Flag Suspicious Activity: Educate employees to recognize and report rapid transitions from chat to voice calls, especially from external or unexpected contacts.
- Monitor for Unusual Software: Implement monitoring for unauthorized remote access tools, suspicious cloud downloads, and unusual SMB activity on endpoints.
- Secure Domain Controllers: Pay close attention to authentication events involving domain controllers, particularly those related to NTLM relay attacks like PetitPotam.
- Comprehensive User Education: Emphasize to employees that legitimate IT staff will never request the installation of unapproved software or demand immediate screen control during an unsolicited call.
- Verify Out-of-Band: Instruct users to independently verify any unexpected support requests by contacting IT through a known, official channel, rather than using contact information provided by the caller.
- Review Teams Audit Data: Regularly audit Teams activity for signs of external collaboration feature abuse, which can help detect early stages of such attacks.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| Attacker identity | helpcenter@ithelpcenter365[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@itprotectiondepartment[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@newsystemmaintenance[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@officedesk365[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@officesecures[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | helpdesk@tbcsschid[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | internal@internalusahelpdeskIT[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | it_assistance@teams0137[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | it@infrastructurefirewall[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | itassistant@bilelonellc[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@certifiednetworksec[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@internalsystemsdaily[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelp@itprotectiondepartment[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | [email protected][.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | support@bilelonellc[.]onmicrosoft[.]com |
Generic help desk identity used in vishing attempts |
| Attacker identity | andreas[..]@idigitalserviceoperation.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | andrew[..]@hapsinfrastructureops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | brandon[..]@devsitoperationhub.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | brian[..]@appssupportsys.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | christopher[..]@adevpsitplatformops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | christopher[..]@itplatformops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | clara[..]@systemsupportoperations.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | daniel[..]@opsnetsupportit.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | daniel[..]@apsitsupporthub.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | emily[..]@apsitechsupportdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | eric[..]@appopshelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | james[..]@helpitsupportcore.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | james[..]@itcoretechhelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | jonathan[..]@itservicedesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | justin[..]@techopshelpsupp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | kevin[..]@itopsupportdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | kevin[..]@netopsdeskhelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | leon[..]@netcorevdapp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | lucas[..]@applicationoperationsunit.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | martin[..]@syslanevdapp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | matthew[..]@supportopsupp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | michael[..]@appdeploymentservices.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | michael[..]@infratechopsdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | michael[..]@itopsdeskhelp.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | patrick[..]@infrastructureopsdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | rachel[..]@ioseccloudsupport.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | rebecca[..]@infrastructureopsservice.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | robert[..]@systemdeploymentcenter.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | ryan[..]@apstechopsdeskdev.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | ryan[..]@helpssupportcloudops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@secinfrahelpdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@apsscloudopsdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@helpitdevsupportops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | sarah[..]@itdevsupportops.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | scott[..]@cloudinfrastr.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | thomas[..]@networkoperationsec.onmicrosoft[.]com |
Partially redacted impersonated username |
| Attacker identity | thomas[..]@seqapsitsupportops.onmicrosoft[.]com |
Partially redacted impersonated username |
| IP address | 193.32.248[.]251 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 193.138.7[.]142 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.65.134[.]209 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 178.130.47[.]46 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 5.181.3[.]106 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 2.56.172[.]214 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.234.67[.]53 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.8.157[.]185 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 80.66.72[.]215 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 136.0.20[.]6 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.213.155[.]226 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.155.99[.]161 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 92.118.232[.]131 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.182.189[.]80 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 185.65.133[.]51 |
VPN or proxy infrastructure used in vishing attempts |
| IP address | 45.33.22[.]47 |
VPN or proxy infrastructure used in vishing attempts |
| Domain | san-sid[.]com |
Attacker-controlled domain hosting the PowerShell RAT payload |
| URL | hxxps[:]//san-sid[.]com/owners |
URL hosting the obfuscated PowerShell RAT dropper |
| SHA-256 | 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b |
Obfuscated PowerShell payload |
| File name pattern | <company_name>-org-filters-update-<victim_name>[.]exe |
Tailored Campaign B executable |
| File name pattern | vhlp-*.exe |
Persistence-related executable copies observed in Campaign B |
| File name pattern | scnr-*.exe |
Persistence-related executable copies observed in Campaign B |



No Comment! Be the first one.