Executive Summary
Between January and April 2026, Palo Alto Networks Unit 42 identified a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as internal IT help desk personnel. The operation, dubbed Spring Ring, targeted more than 150 employees across at least 10 companies in diverse industries. Attackers initiated a voice phishing (vishing) call that coerced victims into executing remote monitoring and management (RMM) tools or custom malware. In an advanced variant, the attackers transitioned from a vishing call to a Microsoft NT LAN Manager (NTLM) relay attack against an organization’s domain controller (DC).
Attack Lifecycle Overview
- Initial Lure – Attackers create a Microsoft Teams chat using external
.onmicrosoft.comtenants that mimic legitimate internal support units. Display names such as “IT Help Desk” or “Support Staff” are used to establish credibility. - Vishing Engagement – Once the chat is accepted, the attacker initiates an audio call. The call lasts from a few seconds to 15 minutes, depending on the victim’s responsiveness. The attacker guides the victim through remote control or malware download instructions.
- Payload Delivery – Two distinct campaign paths were observed:
- Campaign A: Victim is instructed to install a legitimate RMM tool. After remote control is established, a PowerShell‑based remote access trojan (RAT) is downloaded from an attacker‑controlled domain. The RAT uses obfuscation and AMSI bypass techniques.
- Campaign B: Victim clicks a cloud‑hosted executable that mimics the organization’s branding. The executable stages to
\Temp\, launches a headless Microsoft Edge instance, sideloads an extension, and initiates a lateral movement chain using PetitPotam to target the DC.
- Post‑Compromise Behavior – Indicators include atypical RMM tool execution, access to unknown cloud storage URLs, and attempts to exploit NTLM relay vulnerabilities.
Threat Indicators
- External Tenant Patterns – External
.onmicrosoft.comdomains containing keywords like “internal”, “certified”, or “network”. - Display Names – “IT Help Desk”, “Support Staff”, or personalized technician names.
- Source IPs – Commercial VPN or proxy services (e.g., Mullvad).
- Call Metrics – Rapid transition from chat to audio, short initial attempts followed by longer successful sessions.
- Post‑Compromise Artifacts – Obfuscated PowerShell payload (SHA‑256: 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b), cloud‑hosted executables with organization‑specific names.
Mitigation Recommendations
- User Awareness – Train employees to verify the identity of IT personnel before engaging in audio calls. Encourage reporting of suspicious external chats and calls.
- Behavioral Monitoring – Deploy Microsoft Teams user‑behavior analytics to detect rapid chat‑to‑call transitions and unusual call durations.
- Endpoint Protection – Enable AMSI bypass detection and block execution of unknown remote control tools. Use Cortex XDR to monitor RMM tool usage.
- Network Controls – Block outbound connections to known malicious domains (e.g., san‑sid.com) and enforce least‑privilege access for RMM services.
- Identity Security – Leverage Cortex Cloud Identity Threat Detection to flag anomalous external tenant interactions and enforce MFA for all external user access.
Product Protection
- Advanced URL Filtering and Advanced DNS Security to block malicious domains.
- Cortex XDR and XSIAM for holistic endpoint and network visibility.
- Cortex Advanced Email Security to reduce phishing vectors.
- Cortex Cloud Identity Threat Detection to monitor SaaS user behavior.
- Idira Threat Detection and Response, Endpoint Privileged Manager, Privileged Access Management, and Secure Infrastructure Access for privileged account protection.
Conclusion
Spring Ring illustrates a shift from traditional email phishing to weaponizing collaboration platforms. By exploiting the trust placed in Microsoft Teams, attackers can achieve domain‑level compromise with minimal friction. Organizations must prioritize user education, behavioral monitoring, and identity‑centric defenses to mitigate this evolving threat landscape.
“,”excerpt”:”A comprehensive threat report detailing the Spring Ring voice phishing operation in Microsoft Teams, its tactics, indicators, and actionable mitigation strategies.”,”status”:”publish

