Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Cybersecurity Classified by Officially
Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. Our telemetry reveals that this operation targeted more than 150 employees across at least 10 companies in various industries. We call this activity Spring Ring.
What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC).
We provide a technical breakdown of this operation’s attack lifecycle across two observed campaigns, both illustrating vishing manipulation that resulted in the attempted payload delivery via two distinct attack vectors.
These two campaigns demonstrate the weaponization of communication platforms as identity becomes a primary attack vector.
Palo Alto Networks customers are better protected from the threats described here through the following products and services:
If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.
Spring Ring’s activity mirrors a broader trend in the threat landscape toward social engineering campaigns. According to our recently published Insights blog, threat actors have increasingly moved away from traditional phishing techniques toward trusted collaboration tools.
This is an extract. The publication continues at the source.
Read the original at the source: https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
Officially imported this from Palo Alto Networks Unit 42’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Palo Alto Networks Unit 42 — imported from official source
- Official source
- https://unit42.paloaltonetworks.com/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://unit42.paloaltonetworks.com/?p=186248