Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement
Brief
Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution.
The activity ran from January through April 2026 and approached more than 150 employees at at least 10 organizations.
Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate.
Analysts at Unit 42 identified the operation after detecting suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities.
Palo Alto Networks said in a report shared with Cyber Security News (CSN) that the group did not exploit a flaw in Teams.
