Back to Intelligence

Microsoft Teams Help Desk Vishing Campaign: Fake IT Support Delivers Malware for Lateral Movement — OTX Detection Pack

SA
Security Arsenal Team
October 2, 2026
10 min read

Threat Summary

An AlienVault OTX pulse published 2026-10-02 documents an active intrusion campaign in which adversaries impersonate internal IT help desk personnel over Microsoft Teams voice and chat calls to socially engineer employees into executing malicious payloads. This technique — commonly referred to as Teams vishing or callback phishing via collaboration platforms — has been refined over the past two years by both initial access brokers (IABs) and ransomware-affiliated operators, including tradecraft overlapping with groups tracked as Storm-1811 and various Black Basta / Akira affiliates.

The attack chain observed in this campaign follows a consistent pattern:

  1. Reconnaissance & Impersonation — Operators spoof or abuse external Teams federation to appear as internal IT support, often using display names like "Help Desk," "IT Support," or "Tech Admin."
  2. Contact Initiation — The victim receives a Teams call or chat claiming an urgent issue (mailbox quota exceeded, MFA re-enrollment, pending security patch).
  3. Payload Delivery — The victim is instructed to launch Quick Assist, AnyDesk, or download a "fix" — which is actually a malicious executable. The OTX pulse identifies SHA256 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b as a payload sample.
  4. Command & Control — The implant beacons to attacker-controlled infrastructure, including the domain san-sid.com.
  5. Lateral Movement Objective — The pulse title explicitly notes network lateral movement as the end goal, indicating this is an initial access operation feeding larger intrusions (ransomware staging, data theft, or access resale).

The adversary remains unattributed, but the tradecraft strongly matches ransomware enablement ecosystems that monetize corporate footholds within 24–72 hours of initial compromise.

Threat Actor / Malware Profile

Distribution Method: Voice/chat social engineering over Microsoft Teams, exploiting external tenant federation (B2B direct connect) or lookalike tenant accounts. No exploit is required — the "vulnerability" is user trust in collaboration tooling.

Payload Behavior: The delivered binary typically masquerades as an IT remediation tool or update installer. Common behaviors observed in Teams-vishing payloads of this class include:

  • Execution under the context of the user who launched it, often spawned as a child of Teams.exe, QuickAssist.exe, or msedge.exe after a download prompt
  • Dropping secondary payloads (remote access trojans, credential harvesters, or Cobalt Strike beacons) into %APPDATA% or %TEMP% subdirectories
  • Immediate enumeration commands (ipconfig /all, net group "domain admins" /domain, nltest /dclist) to profile the host for lateral movement value

C2 Communication: Beaconing to san-sid.com — treat all DNS resolutions and HTTPS sessions to this domain as confirmed hostile. Expect TLS on 443 with valid-looking certificates to blend with normal traffic.

Persistence Mechanism: Typical persistence for this campaign class includes Run-key registry entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, scheduled tasks masquerading as update jobs, or startup-folder shortcuts.

Anti-Analysis Techniques: Payloads delivered via social engineering often include sandbox evasion (sleep timers, human-interaction checks such as mouse-movement validation), parent-process checks to ensure they were launched by a real user session, and packed/obfuscated PE headers to defeat static signature scans.

IOC Analysis

The pulse contains two operational indicators:

TypeIndicatorOperationalization
Domainsan-sid.comBlock at DNS sinkhole, secure web gateway, and firewall. Alert on any historical resolution in proxy/DNS logs — resolution alone confirms staging or beaconing.
FileHash-SHA25624ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5bPush to EDR blocklists (MDE custom indicators, CrowdStrike IOC management). Hash-based detection catches the exact sample but NOT variants — pair with behavioral rules below.

SOC guidance: Hash IOCs are brittle — adversaries re-pack payloads between victims. The durable detection layer is behavioral: any executable spawned by Teams.exe or QuickAssist.exe is high-signal in most environments. Use VirusTotal, Hybrid Analysis, or ANY.RUN to detonate the hash sample and extract additional network IOCs, then feed those back into your blocklists. Query the domain against passive DNS (SecurityTrails, PassiveTotal) to surface sibling C2 domains on shared infrastructure.

Detection Engineering

YAML
---
title: Suspicious Child Process Spawned by Microsoft Teams or Quick Assist
id: 9f1c4a2e-7b3d-4e5a-8c1f-2d6e9a0b5f41
status: production
description: Detects executable processes spawned by Teams.exe or QuickAssist.exe, consistent with Teams help desk vishing payload delivery where victims are instructed to run a malicious binary during a fake IT support call.
author: Security Arsenal Threat Intelligence
references:
  - https://cybersecuritynews.com/hackers-weaponize-microsoft-teams/
date: 2026/10/03
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\Teams.exe'
      - '\ms-teams.exe'
      - '\QuickAssist.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\msiexec.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\curl.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare legitimate IT tooling launched during genuine Quick Assist sessions
level: high
tags:
  - attack.initial_access
  - attack.t1566
  - attack.t1204
  - attack.t1219
---
title: C2 Communication to san-sid.com Domain
id: 3e8a5d6b-1c2f-4a7b-9d3e-5f8c0a2b6e44
status: production
description: Detects DNS queries or network connections to san-sid.com, an identified command-and-control domain in the Microsoft Teams help desk vishing campaign.
author: Security Arsenal Threat Intelligence
references:
  - https://cybersecuritynews.com/hackers-weaponize-microsoft-teams/
date: 2026/10/03
logsource:
  category: dns
  product: windows
detection:
  selection:
    query|contains: 'san-sid.com'
  condition: selection
falsepositives:
  - None expected; domain is confirmed hostile infrastructure
level: critical
tags:
  - attack.command_and_control
  - attack.t1071
---
title: Post-Compromise Discovery Commands Following User-Context Execution
id: 7c2b9e1a-4d5f-4c8a-b6e2-1a3d5f7c9e02
status: production
description: Detects rapid-fire host and domain enumeration commands commonly executed by vishing-delivered implants preparing for lateral movement, including domain admin discovery and domain controller location.
author: Security Arsenal Threat Intelligence
references:
  - https://cybersecuritynews.com/hackers-weaponize-microsoft-teams/
date: 2026/10/03
logsource:
  category: process_creation
  product: windows
detection:
  selection_cmd:
    CommandLine|contains:
      - 'net group "domain admins" /domain'
      - 'nltest /dclist'
      - 'net localgroup administrators'
      - 'nltest /domain_trusts'
      - 'ipconfig /all'
  filter_legit:
    ParentImage|endswith:
      - '\sccm.exe'
      - '\ccmexec.exe'
  condition: selection_cmd and not filter_legit
falsepositives:
  - Help desk scripts; IT administrative batch jobs — tune per environment
level: medium
tags:
  - attack.discovery
  - attack.t1087
  - attack.t1482
KQL — Microsoft Sentinel / Defender
// Hunt: Teams vishing payload execution + C2 beaconing to san-sid.com
// Microsoft Sentinel — run across the last 14 days

let C2Domain = "san-sid.com";
let PayloadHash = "24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b";

// 1) Network connections to the C2 domain
let C2Hits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has C2Domain or RemoteUrl endswith C2Domain
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, RemoteUrl, RemoteIP, RemotePort;

// 2) Payload hash observed anywhere on endpoints
let HashHits = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where SHA256 == PayloadHash
| project TimeGenerated, DeviceName, FileName, FolderPath, AccountName, InitiatingProcessFileName;

// 3) Teams or Quick Assist spawning suspicious child processes (behavioral)
let SuspiciousSpawn = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName has_any ("Teams.exe", "ms-teams.exe", "QuickAssist.exe")
| where FileName in~ ("powershell.exe","cmd.exe","rundll32.exe","regsvr32.exe","msiexec.exe","mshta.exe","curl.exe","certutil.exe","bitsadmin.exe","wscript.exe","cscript.exe")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine;

// 4) Post-execution discovery activity on devices that spawned from Teams
let Discovery = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where ProcessCommandLine has_any ("net group", "nltest", "domain admins", "ipconfig /all", "net localgroup administrators")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine;

union C2Hits, HashHits, SuspiciousSpawn, Discovery
| sort by TimeGenerated desc
PowerShell
# Teams Vishing IOC Hunt — Security Arsenal
# Run elevated via EDR live response, SCCM, or PS remoting across endpoints
# Checks: C2 connections, payload hash, persistence keys, suspicious Teams child artifacts

$Results = @()
$C2Domain   = "san-sid.com"
$PayloadHash = "24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b"

# 1) Active and recent TCP connections to the C2 domain (resolve cache + netstat)
Write-Host "[+] Checking network connections..." -ForegroundColor Cyan
$conns = Get-NetTCPConnection -State Established,TimeWait -ErrorAction SilentlyContinue
foreach ($c in $conns) {
    try {
        $resolved = Resolve-DnsName -Name $C2Domain -ErrorAction SilentlyContinue
        foreach ($r in $resolved) {
            if ($c.RemoteAddress -eq $r.IPAddress) {
                $Results += [PSCustomObject]@{Check="C2 Connection"; Detail="$($c.RemoteAddress):$($c.RemotePort) OwningPID=$($c.OwningProcess)"; Severity="CRITICAL"}
            }
        }
    } catch {}
}

# 2) DNS client cache for C2 resolution
Write-Host "[+] Checking DNS cache for $C2Domain..." -ForegroundColor Cyan
$dns = Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object { $_.Entry -like "*$C2Domain*" }
if ($dns) { $Results += [PSCustomObject]@{Check="DNS Cache"; Detail=($dns | Out-String); Severity="CRITICAL"} }

# 3) Scan common payload drop locations for the known hash
Write-Host "[+] Hashing files in common drop paths..." -ForegroundColor Cyan
$dropPaths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:USERPROFILE\Downloads","C:\Users\Public")
foreach ($p in $dropPaths) {
    Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue |
      Where-Object { $_.Length -lt 50MB } | ForEach-Object {
        try {
            $h = (Get-FileHash -Path $_.FullName -Algorithm SHA256 -ErrorAction Stop).Hash
            if ($h -eq $PayloadHash) {
                $Results += [PSCustomObject]@{Check="Payload Hash Match"; Detail=$_.FullName; Severity="CRITICAL"}
            }
        } catch {}
    }
}

# 4) Persistence: Run keys (HKCU + HKLM)
Write-Host "[+] Checking Run keys..." -ForegroundColor Cyan
$runKeys = @("HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
             "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run",
             "HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce",
             "HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce")
foreach ($rk in $runKeys) {
    Get-ItemProperty -Path $rk -ErrorAction SilentlyContinue | ForEach-Object {
        $_.PSObject.Properties | Where-Object { $_.Name -notmatch '^PS' } | ForEach-Object {
            if ($_.Value -match 'Temp|AppData|Public|powershell|rundll32|mshta') {
                $Results += [PSCustomObject]@{Check="Run Key"; Detail="$rk :: $($_.Name) = $($_.Value)"; Severity="HIGH"}
            }
        }
    }
}

# 5) Persistence: scheduled tasks pointing into user-writable paths
Write-Host "[+] Checking scheduled tasks..." -ForegroundColor Cyan
Get-ScheduledTask -ErrorAction SilentlyContinue | ForEach-Object {
    $actions = $_.Actions | Out-String
    if ($actions -match 'AppData|Temp|Public' -and $_.TaskPath -notmatch 'Microsoft') {
        $Results += [PSCustomObject]@{Check="Scheduled Task"; Detail="$($_.TaskName) -> $actions"; Severity="HIGH"}
    }
}

# 6) Recent Quick Assist / Teams event artifacts (defense evasion: attackers abuse Quick Assist)
Write-Host "[+] Checking Quick Assist execution artifacts..." -ForegroundColor Cyan
$qa = Get-WinEvent -LogName "Microsoft-Windows-LAPS/Operational" -ErrorAction SilentlyContinue # placeholder-safe
$prefetch = Get-ChildItem "C:\Windows\Prefetch\QUICKASSIST*" -ErrorAction SilentlyContinue
if ($prefetch) { $Results += [PSCustomObject]@{Check="QuickAssist Prefetch"; Detail=($prefetch.Name -join ', '); Severity="MEDIUM"} }

Write-Host "`n===== HUNT RESULTS =====" -ForegroundColor Yellow
if ($Results.Count -gt 0) { $Results | Format-Table -AutoSize | Out-String -Width 300 } else { Write-Host "No indicators found on this host." -ForegroundColor Green }

Response Priorities

Immediate (0–4 hours):

  • Block san-sid.com at DNS resolver, secure web gateway, proxy, and perimeter firewall; add the SHA256 hash to EDR custom block lists.
  • Hunt proxy, DNS, and firewall logs for historical resolutions of the C2 domain going back 30 days — any hit is a confirmed compromised host until proven otherwise.
  • Search Teams message/call audit logs for external tenant contacts matching help desk naming patterns ("IT Support," "Help Desk," "Tech Admin") in the last 14 days.
  • Isolate any endpoint showing Teams or Quick Assist spawning scripting interpreters or LOLBins.

Within 24 hours:

  • If any host executed the payload, assume credential exposure: force password resets and revoke all active sessions/refresh tokens for affected users via Conditional Access and Entra ID.
  • Review MFA registration events for new methods added post-contact — vishing operators frequently attempt MFA fatigue or enrollment during the call.
  • Scope lateral movement: query authentication logs from compromised hosts for anomalous SMB, RDP, WinRM, or Kerberos activity toward servers and other workstations.
  • Interview contacted users to establish exact actions taken during the call.

Within 1 week (architectural hardening):

  • Restrict Teams external access: disable or allowlist external federation ("External access" policies in Teams admin center) so only approved partner domains can message/call users.
  • Block or restrict Quick Assist and unapproved remote access tools via AppLocker/WDAC — if IT support uses a sanctioned RMM, enforce it exclusively.
  • Deploy the Sigma rules above to your SIEM and the KQL query as a scheduled Sentinel analytics rule with high-severity alerting.
  • Launch targeted user awareness training focused specifically on help desk impersonation over collaboration platforms, with a callback-verification policy (users must verify IT contact via a published internal number).

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.