An Inside Look at Voice Phishing Campaigns in Microsoft Teams
released on 2026-08-31 @ 11:06:37 AM
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies. Adversaries initiated voice phishing calls to coerce victims into executing remote monitoring and management tools or custom malware. In advanced variants, attackers transitioned from vishing to NTLM relay attacks targeting domain controllers. Two distinct campaigns were observed: Campaign A utilized RMM tools and obfuscated PowerShell-based RATs, while Campaign B employed tailored cloud infrastructure with PetitPotam exploitation for domain-level compromise. The operation demonstrates the weaponization of trusted collaboration platforms as primary attack vectors, exploiting the trust gap in SaaS applications.