Cybercriminals have launched a coordinated operation, dubbed “Spring Ring,” targeting Microsoft Teams users with sophisticated voice phishing (vishing) attacks. The campaign aims to compromise over 150 users across multiple companies, granting attackers remote access to sessions, spreading malware, and even taking control of infrastructure.
Researchers from Palo Alto Networks observed the Spring Ring operation between January and April, tracking its evolution as it adapted to evade detection. The campaign’s unique approach involves using Microsoft Teams’ trusted collaboration platform as a springboard for vishing attacks, adding an air of authenticity to the interaction. According to Noam Sala, a Palo Alto Networks staff researcher, “The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow.” This shift enables attackers to transition from passive click-and-harvest models to real-time engagement with victims.
At its core, the Spring Ring campaign involves vishing calls that appear as benign chats within Microsoft Teams. Adversaries use these calls to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. A more advanced variant of the attack escalates to a full-blown Microsoft NT LAN Manager (NTLM) relay assault aimed at an organization’s domain controller (DC). This aggressive tactic demonstrates the growing sophistication of cyberattacks, as attackers increasingly leverage trusted collaboration platforms like Microsoft Teams to bypass traditional security measures.
The Spring Ring campaign is part of a broader trend in the threat landscape, where social engineering campaigns are on the rise. According to CrowdStrike’s recent threat-hunting report, vishing attacks doubled in the first half of 2026. This surge in momentum comes with evolution, as attackers adapt their tactics to exploit trusted collaboration platforms.
The attack process begins when an attacker creates a Microsoft Teams chat using identities designed to mirror an organization’s legitimate internal support units. The attacker then initiates a voice call with the victim, pretending to be from the IT department. Once connected, the attacker guides targeted employees through steps to grant remote control or execute malicious payloads.
The researchers observed at least two separate attacks by Spring Ring once engagement with a victim is established. In one scenario, attackers use legitimate RMM software as an entry point, persuading victims to grant remote access before attempting to download an obfuscated PowerShell RAT. In the other variant, attackers execute custom malware, demonstrating their persistence and adaptability in exploiting vulnerabilities.
As organizations continue to rely on collaboration platforms like Microsoft Teams, it’s essential to acknowledge the evolving threat landscape. To protect against vishing attacks, teams should remain vigilant about suspicious interactions within these platforms. Educating employees about the risks associated with voice phishing and encouraging them to verify requests for remote access or execution of malicious payloads can significantly mitigate the impact of such attacks.
To stay ahead of threats like Spring Ring, organizations must prioritize robust security measures, including advanced threat detection tools and regular employee training on cybersecurity best practices. By acknowledging the evolving tactics employed by cybercriminals and taking proactive steps to safeguard their networks, businesses can reduce their vulnerability to sophisticated attacks like those perpetrated by the Spring Ring operation.
Source: Dark Reading — 2026-09-02