Spring Ring Vishing Campaign Exploits Microsoft Teams to Target Corporate Networks
A threat campaign dubbed Spring Ring uses fraudulent Microsoft 365 external tenants to impersonate corporate IT staff via Microsoft Teams chat and voice calls, according to a Unit 42 report published August 31, 2026. Attackers trick employees into granting remote access through RMM tools like Quick Assist or running malicious executables delivered via customized S3 URLs. In more advanced intrusions, the campaign deploys an obfuscated PowerShell RAT and attempts NTLM Relay attacks against domain controllers using the PetitPotam technique to escalate privileges. The attack chain can result in persistent access, hidden browser instances with sideloaded extensions, and lateral movement across internal networks, though NTLM Relay was blocked in observed cases. Security teams are advised to restrict external Teams communication, enforce RMM tool approvals, enable PowerShell and AMSI controls, and harden NTLM relay defenses including SMB signing.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in