The Fake IT Helpdesk Is Calling You on Teams — And It’s Working

teams-helpdesk-malware-thumb

If you work anywhere near a corporate helpdesk queue, you already know the drill: something breaks, you open a ticket, and eventually someone from IT reaches out to fix it. That familiarity is exactly what a growing list of threat actors have decided to weaponize in 2026 — not by breaking into anything, but by asking nicely.

Over the past several months, security researchers at Sophos, Palo Alto Networks’ Unit 42, Google’s Threat Intelligence Group, Expel, and Zscaler ThreatLabz have independently tracked variations of the same basic con: flood a target’s inbox with junk mail, then follow up on Microsoft Teams as “IT support” offering to fix the very problem they just caused. It’s social engineering, not exploitation — and that’s precisely why it’s proven so hard to stop.

The pattern, stripped down

Nearly every campaign researchers have documented this year follows a recognizable shape:

  1. The setup. The target’s inbox gets hit with a wave of spam or junk subscription emails — sometimes disguised as an “employee survey” — enough to be annoying, not necessarily enough to look like an attack on its own.
  2. The contact. Shortly after, someone reaches out via Microsoft Teams, usually from an external tenant, claiming to be internal IT and offering to help with the “issue.”
  3. The ask. The victim is walked into either granting remote access through a legitimate tool — Microsoft Quick Assist, AnyDesk, HopToDesk, or a lesser-known remote support utility called RemSupp — or running a “fix” that’s actually the payload.
  4. The payoff. Depending on the group, that payoff has ranged from remote access trojans to full ransomware deployment.

None of this requires a software vulnerability. It requires a plausible story and a few minutes of a busy employee’s attention.

What’s actually been observed

It’s worth being precise about who’s tracking what here, since these are separate campaigns rather than one coordinated operation:

Sophos attributed a cluster it calls STAC4749 to a financially motivated group running between February and June 2026, concentrated almost entirely on North America — about 95% of the intrusions Sophos observed hit organizations in Canada and the US, spread across services, manufacturing, energy, construction, and IP-heavy legal firms. The attackers used invented IT-support personas (names like Anthony Brooks or Ethan Parker recur in Sophos’s reporting) to talk victims into Quick Assist or RemSupp sessions, which ultimately fed into Chaos ransomware deployments.

Unit 42 described a separate chain starting with a phishing email disguised as an employee survey, followed by a Teams call from a fake IT contact who convinced the target to hand over control of their machine and install a tool like HopToDesk or AnyDesk. From there, an MSI installer dropped a remote access trojan Unit 42 calls EtherRAT.

Google’s Threat Intelligence Group documented a group it’s named UNC6692, active since late December 2025, which inundated inboxes with spam before reaching out on Teams posing as helpdesk staff and pushing a renamed AutoHotKey binary disguised as a mailbox “repair patch.” Google’s writeup flags something worth remembering for defenders: the group leaned on legitimate cloud infrastructure to host and route its traffic — “living off the cloud,” as the report puts it — specifically so the malicious activity blends into ordinary, encrypted, reputably-sourced network traffic instead of standing out.

Expel identified a backdoor it calls SynkLoader, delivered through the same Teams-message-from-“IT” opening line, this time convincing the victim to install something branded as a “PowerShell Cleaner.” It’s not a cleaner — it’s a framework with a fake lock screen for harvesting credentials and an interactive shell for remote control, and notably it was hosted on Microsoft Azure, presumably to borrow some of that platform’s inherent trust.

Zscaler ThreatLabz has been tracking vishing-driven intrusions since January 2026 that lead to a backdoor called GoGRPC, alongside four related malware variants — Lep, Giver, Pet, and Kind — that emerged in stages between January and June.

Five different research teams, five different malware families, one shared social-engineering script.

Why this keeps working

None of this is technically novel. Microsoft first documented this exact technique in connection with Black Basta and a group it tracks as Storm-1811 back in 2024. What’s notable in 2026 is how many unrelated groups have since copied it — which tells you less about any individual actor’s sophistication and more about the technique’s return on investment. A phishing email with a malicious attachment has to survive a mail filter, an EDR agent, and an increasingly well-trained employee. A phone call from “IT” mostly just has to sound plausible.

It also exploits something structural rather than technical: most employees have no reliable way to verify that a Teams contact claiming to be internal IT actually is. External tenant access is often enabled by default, display names are trivial to spoof, and the entire interaction happens inside a tool employees already trust and use daily for legitimate support.

What actually helps

None of these campaigns depended on a zero-day. The mitigations that show up across the vendor writeups are organizational and configuration changes, not patches:

  • Restrict external Teams access, or at minimum require explicit approval before an outside tenant can message employees directly.
  • Treat unsolicited “IT support” contact as suspicious by default — especially one that follows a spike in spam email — and verify it through a separate, already-known channel (a ticketing system, a known internal number) before taking any action.
  • Control which remote-access tools are allowed to run at all. Quick Assist, AnyDesk, and HopToDesk are legitimate software; the problem is an unmanaged environment where any of them can be installed and used by anyone, including someone who just called out of nowhere.
  • Watch for the installer, not just the payload. Several of these chains route through an MSI package or a renamed, otherwise-legitimate binary (AutoHotKey, in UNC6692’s case) specifically to slip past tools looking for obviously malicious executables.

The uncomfortable throughline across all five reports is that the technical controls mostly worked as designed — the compromise happened because a human, in good faith, did what a tool that sounded like their own IT department asked them to do. That’s a training and process gap as much as a security-tooling one, and it’s the reason this technique has spread across so many unrelated criminal groups in a single year: it works on people, not on infrastructure, and people are the one thing every organization has in common.


This piece draws on public reporting from Sophos, Palo Alto Networks Unit 42, Google’s Threat Intelligence Group, Expel, and Zscaler ThreatLabz. Campaign names, timelines, and technical details reflect those vendors’ own attribution and analysis; where a detail is a vendor’s assessment rather than a confirmed fact, that distinction is preserved above.

Sources:

Leave a Reply

Your email address will not be published. Required fields are marked *

About Author

Subhash Thapa

Security Analyst (SOC, AI, MDR & IR) | CEH | CCSP | CCIO | CSFPC

Weekly threat intel, straight to your inbox

Free. No noise. Unsubscribe anytime.

Categories