Teams Help Desk Calls Used as Entry Point for Malware and Network Compromise
Attackers are increasingly using Microsoft Teams help desk calls as an entry point for malware and network compromise. A campaign tracked as Spring Ring targeted at least 10 organizations, approaching over 150 employees between January and April 2026.
The attackers would initiate a one-to-one chat from external accounts with authoritative display names such as 'help desk' or 'IT assistance.' They would then place unsolicited voice calls, sometimes leaving voicemails and repeatedly trying different targets.
Once successful conversations were established, the attackers would guide employees into launching remote support utilities or downloading malware. In some cases, they used PowerShell to retrieve an obfuscated remote-access trojan from their infrastructure.