Fake IT Helpdesk Tricks Users Into Remote Access

The Hacker News · High sophistication
Last updated September 3, 2026

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or handing over credentials, which can lead to full enterprise compromise.

Key findings

  • Microsoft described a campaign where attackers use external Microsoft Teams collaboration to impersonate IT/help desk and talk users into granting interactive remote sessions.
  • Unit 42 reported “Spring Ring,” using Teams chat that turns into vishing calls to pressure victims into running RMM tools or malware, impacting 150+ employees across 10+ companies.
  • A phishing-as-a-service kit (“Outsider,” operated by “ChenLun”) continued after takedowns, delivering SMS phishing at scale and using tooling like live keylogging and MFA manipulation.
  • A “BlueKit” turnkey service targeted CEOs in financial organizations using document-sharing lures and a browser-in-the-middle flow for credential/session theft, sometimes followed by a fake document viewer that installs a legitimate ScreenConnect client connected to attacker infrastructure.
  • A counterfeit download site (“www.mxsetuplogi.com”) was promoted via sponsored search; a single mistyped domain (“www.mxsetup.logi.con”) routed a victim into an installer that enabled remote command-driven mouse/keyboard control.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, IT, Service Desk.
  • Affected industries: Finance, Technology / Software, Defense contractors, Fortune 500 (mixed industries).
  • Attack channels: teams, vishing, website.
  • Impersonated: IT or help desk personnel, IT help desk personnel, A legitimate mouse setup/download site (lookalike domain).

Awareness takeaways

  • Treat unexpected IT/support contacts in Teams (especially external accounts) as suspicious and verify through your normal helpdesk channel before granting access.
  • Never start or approve remote-control sessions just because someone asked in chat or on a call; require a ticket and verified identity first.
  • Be cautious with document-sharing and “viewer” workflows that lead to software installs, attackers may use legitimate tools connected to attacker infrastructure.
  • Use bookmarks and double-check domains before downloading software; a one-letter typo can redirect you to a malicious site.

Red flags to watch for

  • Unexpected IT contact via external Teams collaboration
  • Pressure to start a remote session immediately
  • “Help desk” contact coming from outside the organization
  • Teams message from an external account claiming to be IT
  • Conversation quickly escalates to a voice call
  • Request to install remote monitoring tools not initiated via standard ticket process
  • Lookalike domain name / typo in the URL
  • Sponsored search result instead of trusted bookmark/vendor site
  • Unexpected download during routine setup
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a Teams chat pops up, “Hi, this is IT, we need a quick remote session to fix your account.” Looks normal, right? Microsoft’s seen real campaigns where external accounts on Teams impersonate the help desk, then jump to a vishing call and talk people into installing remote tools or granting a full interactive session. Others go further: a shared “document” opens a fake viewer that quietly installs a legit ScreenConnect client wired to their servers, or a one-letter typo like mxsetup.logi.con sends you to a fake download site that gives them mouse and keyboard control. Here’s the move: if “IT” contacts you out of the blue in Teams or by phone and wants a remote session or install, stop and open our official helpdesk portal yourself to verify before you do anything.

Similar attacks

Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026