⚠️ Region Alert: UAE/Middle East
The "Spring Ring" operation is a coordinated social engineering campaign active between January and April 2026, targeting over 150 employees across at least 10 companies. Attackers utilize external Microsoft Teams accounts to impersonate IT help desk personnel, leveraging the platform's trusted status to initiate voice phishing (vishing) calls. These calls aim to coerce victims into executing remote monitoring and management (RMM) tools or custom malware.
Two distinct campaign variants were observed: Campaign A involved luring users into running RMM software to deliver an obfuscated PowerShell-based Trojan, while Campaign B used tailored cloud endpoints to deploy persistent malware. Campaign B notably escalated to NTLM relay attacks using the PetitPotam tool, attempting to gain domain-level privileges. This operation highlights a strategic shift where identity becomes a primary attack vector within enterprise collaboration platforms.
Top comments (0)