DEV Community

Mark0
Mark0

Posted on

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

⚠️ Region Alert: UAE/Middle East

The "Spring Ring" operation is a coordinated social engineering campaign active between January and April 2026, targeting over 150 employees across at least 10 companies. Attackers utilize external Microsoft Teams accounts to impersonate IT help desk personnel, leveraging the platform's trusted status to initiate voice phishing (vishing) calls. These calls aim to coerce victims into executing remote monitoring and management (RMM) tools or custom malware.

Two distinct campaign variants were observed: Campaign A involved luring users into running RMM software to deliver an obfuscated PowerShell-based Trojan, while Campaign B used tailored cloud endpoints to deploy persistent malware. Campaign B notably escalated to NTLM relay attacks using the PetitPotam tool, attempting to gain domain-level privileges. This operation highlights a strategic shift where identity becomes a primary attack vector within enterprise collaboration platforms.


Read Full Article

Top comments (0)