DEV Community

Mark0
Mark0

Posted on

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

⚠️ Region Alert: UAE/Middle East

The Spring Ring operation is a coordinated social engineering campaign identified between January and April 2026, targeting over 150 employees across various industries. Attackers utilize external Microsoft Teams accounts to masquerade as IT help desk personnel, initiating voice phishing (vishing) calls to manipulate victims into executing remote monitoring and management (RMM) tools or custom malware. This activity represents a significant shift in threat actor behavior, moving away from traditional email phishing toward trusted SaaS collaboration platforms to exploit the "Chat with Anyone" feature.

Technically, the operation bifurcates into two distinct campaigns: Campaign A focuses on RMM execution and the delivery of obfuscated PowerShell-based remote access Trojans (RATs), while Campaign B employs more sophisticated methods, including tailored cloud-hosted executables and browser hijacking. In advanced instances, attackers transitioned to NTLM relay attacks using the PetitPotam tool, aiming to achieve domain-level privileges by coercing domain controllers into authenticating with attacker-controlled infrastructure. The campaign highlights how identity has become the new primary attack perimeter.


Read Full Article

Top comments (0)