Microsoft Teams phishing scam steals accounts
Attackers pretend to be IT help desk staff on Microsoft Teams, then call employees and talk them into installing remote access software or malware. Once inside, they can steal data or try to take over the whole company network.
- Report priority
- Medium
- Targets
- Microsoft 365
How it works
An outside attacker creates a Microsoft Teams account made to look like internal IT support, then starts a chat and a live voice call with an employee, and talks the employee into running a remote access tool like Quick Assist or downloading a file from a cloud storage link, which then installs a hidden remote access trojan or a malicious browser extension.
What to do
If you received an unexpected Teams chat or call from an outside account claiming to be IT support between January and April 2026, or a similar one since, check whether your organization allows external Teams contact by default and whether anyone was asked to run Quick Assist or download a file from a link.
There is no personal software patch for this since it relies on tricking people, so never grant remote control or run downloads because of an unsolicited Teams call, verify IT support requests through a known internal channel, and organizations should restrict or disable external Teams communication in Microsoft 365 admin settings and watch for the alert patterns Palo Alto Networks Unit 42 describes.
Technical details
Affected software: Microsoft 365
An attacker creates an external Microsoft Teams account named something like Help Desk or IT Support and messages an employee out of the blue. During a live call the attacker convinces the employee to open Quick Assist and hand over remote control of their computer. The attacker then checks the employee's group and domain details and quietly installs a disguised remote access trojan that turns off built in malware scanning, encrypts files on the machine, and sends data to an outside server.
Dubbed Spring Ring by Palo Alto Networks Unit 42, this vishing campaign abused Microsoft Teams' external-tenant chat feature (accounts on the external.onmicrosoft.com domain, named things like Help Desk or MandatoryNetworkMonitoring) to reach over 150 employees across 10+ companies between January and April 2026. After a live voice call, victims were guided to run Quick Assist for remote access, leading to an obfuscated RAT that disables AMSI, encrypts host data, and beacons out. A second path used a company-named cloud storage link that dropped an executable which hid in temp folders, sideloaded a malicious Edge extension, and ran Python-based internal network scans attempting NTLM relay attacks against the domain controller.