A coordinated social engineering campaign has targeted more than 150 employees across at least 10 organizations by abusing Microsoft Teams to impersonate internal IT support staff.
Tracked as Spring Ring, the campaign was active between January and April 2026 and combined voice phishing, remote monitoring and management (RMM) tools, custom malware, and NTLM relay techniques.
The attackers first created external Microsoft Teams accounts using professional-looking names such as “Help Desk,” “IT Assistance,” and “Network Support.”
Many accounts used attacker-controlled .onmicrosoft.com tenants designed to make the identities appear connected to legitimate corporate infrastructure. After initiating a chat, the attackers called victims and posed as IT technicians.
The voice interaction was central to the attack. Rather than relying only on malicious links, the threat actors used real-time conversations to build trust and persuade employees to perform actions on their computers.
Some calls lasted 10 to 15 minutes, while others were short or resulted in voicemails.
Teams Vishing Targets Employees
In Campaign A, attackers convinced victims to launch legitimate remote-support software such as Quick Assist or third-party RMM tools. After obtaining remote access, they performed basic reconnaissance using commands including whoami /groups and net group /dom.
The attackers then used PowerShell to download an obfuscated remote access Trojan from the attacker-controlled domain san-sid[.]com.

The nine-line payload attempted to disable the Antimalware Scan Interface (AMSI), collect host information, encrypt data, and communicate with the command-and-control server. Automated endpoint protection blocked the malware during execution.
Campaign B used a more customized infection chain. Victims were directed to cloud-hosted executables whose filenames included the targeted company and employee name.
After execution, the malware moved into the temporary directory, created additional copies for persistence, and launched a hidden Microsoft Edge instance.
The attackers also sideloaded a browser extension and used a bundled Python executable for further activity. The malware generated SMB traffic toward internal systems and triggered NTLM authentication attempts against the organization’s domain controller.

The attackers then attempted to use PetitPotam to coerce the domain controller into authenticating to an attacker-controlled system.
This could enable an NTLM relay attack capable of escalating access toward domain-level privileges. The attempted domain takeover was blocked by security monitoring.
Spring Ring highlights how collaboration platforms can become powerful social engineering channels.
External Teams identities can appear more trustworthy than conventional phishing emails, while voice calls provide attackers with an opportunity to respond immediately to a victim’s questions and resistance, unit42 said.
Several behavioral indicators can help defenders identify the campaign. These include unsolicited Teams chats from external users, rapid transitions from chat to voice calls, unusual RMM execution, unexpected cloud-storage downloads, rare browser extensions, and abnormal SMB or NTLM activity.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN