Criminals Pose as IT Support Inside Microsoft Teams to Take Over Company Networks
A hacking campaign called Spring Ring tricked more than 150 employees at ten-plus companies into handing over remote control of their computers, all through a fake Teams call from a fake help desk.

Key points
- Spring Ring attacked at least 150 Microsoft Teams users across more than 10 organisations between January and April 2025.
- Criminals posed as internal IT support staff, calling victims directly through Teams to trick them into installing remote-access software.
- A second, more dangerous attack variant attempted to seize control of an organisation's entire identity system, the directory that manages every user account.
- Vishing (voice-based phishing, where criminals impersonate someone trusted over a call rather than in an email) doubled in the first half of 2025, according to CrowdStrike.
- Palo Alto Networks' Unit 42 research team blocked the most advanced attack attempts before they caused lasting damage.
Your phone rings inside Microsoft Teams. The caller ID says "IT Help Desk." A friendly voice explains there is a security problem with your account and walks you through a quick fix. Fifteen minutes later, criminals have full access to your computer.
That is the Spring Ring playbook.
Researchers at Palo Alto Networks spent the first four months of 2025 tracking a coordinated campaign that hit at least 150 employees across more than 10 companies. First reported in depth by Dark Reading, the operation exploits the trust people naturally place in their company's collaboration tools.
How did the attack actually work?
Criminals created fake Teams accounts with names designed to look like official internal support, words like "Help Desk," "IT Assistance," or "Support Staff." They initiated a chat, then called.
Once a victim answered, the caller guided them step by step. The simpler version convinced employees to use Windows Quick Assist, a built-in screen-sharing tool, or similar remote-management software, handing the criminals direct keyboard-and-mouse control of the machine.
The nastier version went further. Victims were directed to download files from cloud storage, files that turned out to be malicious programs. Those programs quietly launched a hidden web browser session, installed a rogue browser extension, and began probing the internal network. The goal was a PetitPotam NTLM relay attack, which works by tricking a company's main user-account server (called a domain controller) into sending its login credentials to a machine the criminals control. Pull that off and you can, in theory, reset passwords and access every system in the organisation.
Unit 42's monitoring service caught and blocked the attempt.
| Attack stage | What the criminals did | Outcome |
|---|---|---|
| Initial contact | Fake "Help Desk" Teams chat and call | Victim engagement |
| Vector 1 | Persuaded victim to share screen via Quick Assist | Blocked by endpoint protection |
| Vector 2 | Victim downloaded malicious executable from cloud link | Hidden browser and network probe launched |
| Final goal | PetitPotam relay attack against domain controller | Blocked by Unit 42 managed detection |
Should employees be worried?
Yes, but the fix is straightforward awareness, not technical expertise.
The entire attack rests on one assumption: that you will not question an unexpected call from someone claiming to be your own IT department. Denis Calderone, chief technology officer at Suzu Labs, puts it bluntly. Standard security training telling people to check the sender and avoid clicking links does not prepare anyone for a live phone conversation. Organisations need to rehearse the real scenario so staff feel that instinctive unease, what Calderone calls "getting your Spidey sense tingling," when an unfamiliar person suddenly calls and asks them to run software.
If you receive an unexpected Teams call from someone claiming to be IT support, hang up and call your actual IT team back on a number you find yourself. Legitimate help desks do not cold-call employees and ask for remote access without a prior support ticket.
MFA, meaning multi-factor authentication (where logging in requires a second proof of identity, like a code sent to your phone), would not have stopped this particular attack on its own. The criminals were not stealing passwords; they were convincing real, logged-in employees to hand over control voluntarily. Human judgement is the primary defence here.



