Microsoft Teams phishing calls trick employees into malware

Published August 20, 2026

Attackers pose as IT support in Microsoft Teams calls to trick employees into running malware or giving remote access. This lets them move from one computer to others on the network.

Report priority
Medium
Targets
Microsoft

How it works

Attackers create fake Teams accounts addresses and start private chats with employees, then call them pretending to be IT support.

What to do

Check if you received unexpected Teams calls from unknown accounts or numbers between January and April 2026.

Do not trust unsolicited Teams calls or chats from unknown accounts. If you receive one, end the call immediately and report it to your IT department.

Technical details

An attacker creates a fake Microsoft Teams account using email. They start a private chat with a victim employee, then call them pretending to be IT support. The attacker claims there is a problem with the victim's computer and asks them to run a remote support tool or download a file. The victim, believing it is a real IT request, follows the instructions, allowing the attacker to install malware or gain remote access to their computer. From there, the attacker can move to other computers on the network.

A social engineering campaign called Spring Ring abused Microsoft Teams' external communication features to compromise employees between January and April 2026. Attackers created fake help desk accounts using.onmicrosoft.com domains with names like "IT Assistance" or real employee names to impersonate internal support. They initiated one-to-one chats, followed up with unsolicited voice calls, and persuaded victims, often in 10-15 minute conversations, to grant remote access via tools like Quick Assist or install remote monitoring software.

Once access was granted, attackers used PowerShell to deploy an obfuscated remote-access trojan, enabling lateral movement across the victim's network. The campaign targeted over 150 employees at least 10 organizations, demonstrating how Teams impersonation exploits trust in workplace collaboration tools. Researchers at Palo Alto Networks' Unit 42 identified the operation after detecting suspicious chat activity across multiple Microsoft 365 tenants.

No software vulnerability was exploited.