Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control
Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control
Read Time:3 Minute, 9 Second

A social-engineering campaign used Microsoft Teams chats and live help-desk calls to persuade employees to surrender remote control of their computers, providing attackers with a route from one workstation toward wider network access. The operation, tracked as Spring Ring, approached more than 150 employees at at least 10 organizations between January and April 2026.

Trusted collaboration became the phishing channel

The attackers did not need a software flaw in Teams. They created external Microsoft 365 accounts with authoritative display names such as IT support or help desk, then initiated one-to-one chats from attacker-controlled onmicrosoft.com tenants. Some profiles borrowed the names of real people, making an unfamiliar contact appear more credible.

After opening a chat, operators placed unsolicited voice calls, left messages and tried multiple employees. Successful calls often lasted 10 to 15 minutes. That live interaction gave the impersonator time to answer objections, manufacture urgency and guide the target through actions that might look suspicious in an email.

Remote assistance delivered malware

In one branch of the campaign, the caller convinced victims to start Microsoft Quick Assist or install remote monitoring and management software. After receiving control, the intruder inspected the host and its domain, then used PowerShell to retrieve an obfuscated remote-access trojan. A legitimate support capability effectively became the delivery mechanism because the employee authorized the session.

A second branch used a cloud-hosted executable customized with the target company and employee name. The program copied components into temporary storage for persistence and launched a hidden Edge process with a sideloaded extension. Attackers then used Python-based tooling to scan internal systems over SMB and generate NTLM authentication traffic toward the domain controller.

The campaign aimed beyond one endpoint

Investigators observed an attempted PetitPotam technique designed to force a domain controller to authenticate to an attacker-controlled system. That authentication could potentially be relayed to gain more powerful access. The takeover attempt was blocked, but the chain demonstrates how quickly a believable support call can evolve into an enterprise identity incident.

The operation is a form of voice phishing, or vishing, adapted to the workplace platform employees already use. Its effectiveness depends on familiarity and speed: a support-themed display name, an immediate call and instructions delivered conversationally can suppress the pause that normally helps users identify fraud.

Controls should address people and platform settings

  • Restrict external Teams communication to business requirements and clearly label outside participants.
  • Require employees to verify unexpected support contacts through a known internal channel.
  • Alert on rapid transitions from external chat to calls, remote-assistance launches or new RMM installations.
  • Monitor PowerShell downloads, unusual SMB scanning and NTLM events involving domain controllers.
  • Block unapproved remote-access tools and give staff a simple way to report suspicious accounts.

Training should be precise rather than generic. Employees need to know that legitimate IT staff will not unexpectedly ask them to install an unapproved tool or grant screen control during an unsolicited call. Support teams can reinforce this rule by publishing their normal contact process and using ticket identifiers that workers can independently confirm.

Identity defenses must cover collaboration tools

Email is no longer the only front door for impersonation. Teams audit data, external-tenant activity and remote-support telemetry deserve the same attention organizations give suspicious messages and links. Endpoint controls can break the chain after a user is deceived, while identity monitoring can reveal attempted movement toward privileged systems.

Spring Ring shows that attackers can combine ordinary product features with patient human manipulation and familiar administrative tools. The strongest immediate defense is also the simplest: stop the conversation, verify the request out of band and report the external identity before opening any utility. Technical controls should make that cautious behavior easier—and contain the damage when persuasion succeeds.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control, use the discussion on Forum.

>> forum community

Comments

Leave a Reply