Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users

Cyber attackers have been using a new tactic to compromise Microsoft Teams users, according to researchers from Palo Alto Networks. The “Spring Ring” operation has targeted at least 150 employees across multiple companies with voice phishing (vishing) attacks that aim to install remote monitoring and management tools on their machines.

The campaign is significant because it marks a shift away from traditional email phishing towards attacks conducted through trusted enterprise collaboration platforms like Microsoft Teams. This adds authenticity to the interaction, making it harder for victims to detect the scam. “The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow,” said Noam Sala, a Palo Alto Networks staff researcher.

The attacks begin with a seemingly benign chat on Microsoft Teams that is actually a vishing call. Adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. A more advanced variant of the attack goes even further, with attackers moving from a vishing call “to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization’s domain controller (DC),” Sala added.

Vishing is on the rise, according to a recent threat-hunting report from CrowdStrike, which found that attacks doubled in the first half of 2026. The Spring Ring campaign shows that with this momentum also comes evolution, with attackers focusing on trusted collaboration platforms as a springboard for vishing attacks. “Spring Ring’s activity mirrors a broader trend in the threat landscape toward social engineering campaigns,” Sala wrote.

The attackers behind Spring Ring demonstrate persistence in their efforts to engage with victims, making several attempts and even leaving voicemails in an effort to connect with victims. Once connected, successful vishing calls end up lasting between 10 and 15 minutes, according to Sala.

The two attack vectors used by Spring Ring are particularly noteworthy. The first uses legitimate remote access tools as the entry point, persuading victims to use Windows Quick Assist or third-party RMM software to give the attacker remote control. The threat actor then performs basic host and domain reconnaissance before attempting to download an obfuscated PowerShell RAT in activity that was ultimately blocked by endpoint protection.

The second attack vector goes even further, with attackers moving from a vishing call “to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization’s domain controller (DC),” Sala added. This attack allows the threat actor to gain access to sensitive information and compromise the entire network.

Overall, the Spring Ring campaign highlights the growing sophistication of cyber attackers and their ability to adapt to new technologies like Microsoft Teams. It also underscores the importance of educating employees on vishing attacks and the need for organizations to implement robust security measures to prevent such attacks from succeeding.

As a practical takeaway, it’s essential for users to be cautious when receiving unexpected voice calls or messages on collaboration platforms. Always verify the identity of the caller by contacting them through other means, and never grant remote access or execute malicious payloads without proper authorization.


Source: Dark Reading — 2026-09-02