Teams Helpdesk Vishing Pushes Remote Control Tools

Unit 42 · High sophistication
Last updated August 31, 2026

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or run malware, including downloads from attacker-controlled domains and tailored cloud links that looked company-specific.

Key findings

  • Operation ran between January and April 2026 and targeted “more than 150 employees across at least 10 companies.”
  • Attackers used external Microsoft Teams accounts and professional display names to impersonate internal IT/help desk staff.
  • The lure progressed from a Teams chat to a voice call, then to persuading users to run remote access tools or download malware.
  • Campaign A relied on legitimate remote support/RMM tools (including Quick Assist) followed by PowerShell-based malware from an attacker-controlled domain (san-sid[.]com).
  • Campaign B used tailored cloud-hosted links and filenames that included the company name and victim name, increasing trust and click-through.
  • Researchers observed repeated call attempts (including voicemails), with successful calls commonly lasting 10–15 minutes.

Who’s being targeted

  • Commonly targeted roles: All employees, IT Service Desk, IT Support, Security Operations (SOC), Executives and admins (high-trust targets).
  • Affected industries: Multiple industries (cross-industry targets).
  • Attack channels: teams, vishing, website.
  • Impersonated: Internal IT Help Desk / Support technician, Internal IT / Network Security team.

Awareness takeaways

  • Treat unexpected Microsoft Teams chats/calls, especially from external accounts, as potential phishing, even if they look like ‘Help Desk.’
  • Never grant remote control or install remote-support tools (e.g., Quick Assist/RMM) based solely on an inbound call; verify via your official IT channel first.
  • Be suspicious of ‘company-branded’ cloud download links and installers that include your name; personalization can be a social-engineering tactic.
  • Repeated call attempts/voicemails and urgent language are common pressure tactics, slow down and confirm identity before acting.

Red flags to watch for

  • Teams chat/call comes from an external tenant (.onmicrosoft.com) pretending to be internal IT
  • Unexpected request to grant remote control during an unsolicited help desk call
  • High-pressure urgency and repeated call attempts/voicemails
  • Installer link and filename contain personalized/company text to appear trustworthy
  • Download is from a cloud hostname the user has never seen/verified
  • IT request arrives via unsolicited external Teams contact and voice call
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a Teams ping: “Hi, this is IT Help Desk, we need a quick call about a required update.” Looks normal, right? Between January and April 2026, more than 150 employees got this: chat turns into a voice call, and the ‘tech’ walks them through opening Quick Assist or installing a remote tool so they can “fix” an urgent issue. In some calls, they send a cloud link like company-org-filters-update-yourname.exe on an S3 URL you’ve never seen. It has your company and your name in it on purpose, just to make you click and run their malware. If an unexpected Teams “help desk” call asks for remote control or to run an installer, hang up and contact IT using your normal help desk channel, don’t do anything from that call.

Similar attacks

Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026