Attackers used fake IT-support identities and live Microsoft Teams calls to persuade employees to grant remote access or run malware. Palo Alto Networks Unit 42 says the Spring Ring campaign targeted more than 150 employees at 10 or more companies between January and April 2026. Its report describes two separate attack paths, and says both observed intrusion attempts were blocked before the attackers reached their objectives. Unit 42 found no evidence that Microsoft Teams was compromised or that a Teams vulnerability was involved.
How did the Teams malware scam work?
The attackers started conversations from external Microsoft Teams tenants with names resembling internal IT departments. Some used individual names to sound more credible. Once an employee accepted a chat, the attacker called and posed as a technician, using a real-time conversation to persuade the person to take action.
Unit 42 observed 26 distinct attacker identities. Successful calls often lasted 10 to 15 minutes, while other attempts were missed or ended within seconds. The report describes the calls as the persuasion stage: what followed depended on which of two attack paths the caller used.
These figures come from Unit 42’s observations of this campaign, not a count of all Teams attacks. Unit 42 also reported that Teams-based activity accounted for 42% of phishing alerts in its Cortex telemetry during the first four months of 2026, compared with 30% in the preceding four months. Separately, Unit 42 cited KnowBe4’s report of a 41% increase in Teams-based attacks from October 2025 to March 2026. Those are different measurements, with different sources and denominators; neither figure represents the share of all organizations that were attacked.
#1 Best Overall
What were the two attack paths?
The two routes shared a fake help-desk identity and a Teams call, but diverged after the employee was persuaded. Unit 42 describes them as distinct observed paths, not as consecutive stages of one infection.
| Stage | Remote-support route | Tailored executable route |
|---|---|---|
| How control or execution began | The caller instructed the employee to open Windows Quick Assist or download third-party remote-support software and grant control. | The caller sent a link to a cloud-hosted executable named to include the employee’s organization and name. |
| Observed activity | The attacker ran basic host and domain checks, then used an obfuscated PowerShell command to download a remote-access Trojan. The malware attempted to disable the Antimalware Scan Interface and contact attacker infrastructure for further payloads. | The executable established persistence, launched a hidden Microsoft Edge instance, sideloaded an extension, scanned internal systems over SMB, and attempted a PetitPotam NTLM relay against a domain controller. |
| Reported outcome | Unit 42 says Cortex XDR blocked the campaign during malware execution. | Unit 42 says its managed detection and response blocked the attempted domain takeover. |
Unit 42 characterizes both cases as attempted intrusions, not successful compromises of the organizations involved.
Rank #2
Was Microsoft Teams hacked?
Unit 42 found no evidence of a Microsoft product compromise or vulnerability connected to Spring Ring. In this campaign, Teams supplied the chat and calling channel; the attackers relied on impersonation and the employee’s actions to try to gain access or execute software. As Unit 42 researchers put it, “Threat actors frequently abuse or subvert legitimate products for malicious purposes. This does not indicate that the product itself is flawed or compromised.”
Can someone send me malware through a Teams call?
A call itself does not install malware. The risk in this campaign came when a caller persuaded someone to grant control through remote-support software or to open a linked executable. Treat an unexpected IT call as unverified even when the caller sounds knowledgeable or uses a familiar-looking department name.
- Do not grant remote access or install a tool because an unsolicited caller asks you to.
- Do not open an executable sent in an unexpected chat. Verify the request through a separate, known IT contact or approved support process.
- Report the chat, caller, link, or file using your organization’s security procedure. Do not continue the conversation to test whether the caller is genuine.
How can IT teams spot fake help-desk messages on Microsoft Teams?
Unit 42 identifies suspicious external identities, quick transitions from chat to a call, unexpected links, and unusual remote-management activity as useful points for scrutiny. A practical review should connect the social-engineering signal with what happened on the endpoint and network afterward.
- Review external contacts: Check whether an unfamiliar tenant or account is claiming to be internal IT, particularly when the display name resembles a department or staff member.
- Correlate chat and call timing: A call soon after an unsolicited chat can be a clue when paired with a request for control, software installation, or file execution.
- Investigate remote-support use: Confirm that Quick Assist or third-party remote-management software was expected, authorized, and initiated through a trusted support workflow.
- Look for suspicious execution: Investigate unusual PowerShell activity, attempts to weaken antimalware scanning, unexpected persistence, or a hidden browser instance and sideloaded extension.
- Check internal movement: Review unexpected SMB scanning and NTLM-relay activity, including attempts involving domain controllers.
- Prepare users: Teach staff how to verify support requests and report unsolicited collaboration-platform contact. Unit 42 recommends user education about such communications.
Unit 42’s technical observations include products and services from Palo Alto Networks, including Cortex XDR and XSIAM. Those descriptions are the vendor’s own reporting and are not independent product evaluations.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

