Cybercriminals have found a new way to infiltrate networks by exploiting Microsoft Teams help desk calls, transforming them into vectors for malware distribution and network breaches. The Spring Ring campaign, active from January to April 2026, targeted over 150 employees across at least 10 organizations. Attackers used external accounts that mimicked internal IT support, engaging employees through chats and unsolicited calls to gain access to systems.

Unit 42 analysts discovered this operation while monitoring suspicious activity across Microsoft 365 tenants, identifying 26 different attacker identities. Palo Alto Networks reported that the attackers did not exploit any vulnerabilities within Teams itself. Instead, they leveraged external communication capabilities and the inherent trust users place in collaboration tools.

The attackers used authoritative display names, such as 'help desk' or 'IT support', to initiate one-on-one Teams conversations. Following this, they placed unsolicited voice calls, sometimes leaving voicemails to increase their chances of success. These calls, often lasting 10 to 15 minutes, were used to persuade employees to install remote support software or execute malicious programs.

In one instance, victims were tricked into launching Quick Assist or downloading remote monitoring software. Once remote access was established, attackers used PowerShell to deploy a remote-access trojan. Another scenario involved a tailored executable designed to persist in the system and facilitate unauthorized access to domain controllers, although the attempt was thwarted.

This campaign underscores the importance of scrutinizing Teams impersonation as much as email phishing. Organizations should restrict external Teams communications to essential business needs and remain vigilant for rapid shifts from chat to calls. Educating users to independently verify unexpected support requests and monitoring for unusual activity can prevent these attacks from escalating into significant breaches.