Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
Unit 42 details 'Spring Ring', a vishing campaign using fake IT support on Microsoft Teams to reach 150+ employees at 10+ companies.
Palo Alto Networks Unit 42 documented 'Spring Ring', a voice-phishing campaign that ran January to April 2026, using 26 attacker identities and fake Microsoft 365 tenants such as 'ITProtectionDepartment' to impersonate internal IT support on Microsoft Teams. One path used Quick Assist or downloaded remote-support tools to run an obfuscated PowerShell script that disabled malware scanning before contacting C2; the other delivered a cloud-hosted file triggering browser hijacking, SMB internal network scanning, and a PetitPotam NTLM relay attempt against domain controllers to gain domain-level privileges. Both intrusion attempts were blocked before attackers reached their objectives. Collaboration-platform phishing alerts rose to 42% of Unit 42's telemetry in early 2026, up from 30%.
- Attackers registered onmicrosoft.com tenants like 'ITProtectionDepartment' to impersonate internal IT departments.
- 26 distinct attacker identities conducted chats and calls targeting 150+ employees at 10+ companies.
- PetitPotam NTLM relay aimed to make domain controllers authenticate to attacker machines for domain-level privileges.
- Collaboration-platform phishing alerts rose from 30% to 42% of Unit 42's telemetry in early 2026.
- Successful vishing calls typically lasted 10 to 15 minutes.
Full article489 words · extracted from helpnetsecurity.com · click to collapse
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team.
The campaign ran between January and April 2026 and reached more than 150 employees at more than 10 companies in different industries.
The attackers registered external Microsoft Teams tenants with names built to resemble internal IT departments, such as “ITProtectionDepartment” or “MandatoryNetworkMonitoring,” using the onmicrosoft.com format that Microsoft 365 customers normally use for their own organizations, Unit 42 found.
Some attackers used specific names, rather than generic titles like “help desk,” to increase the perceived authenticity of the technician on the other end of the line.
“Threat actors frequently abuse or subvert legitimate products for malicious purposes. This does not indicate that the product itself is flawed or compromised,” researchers noted.
Unit 42 identified 26 distinct attacker identities behind the chat and call attempts.
Once a chat was accepted, the attacker placed a call. Many attempts were missed or lasted only seconds, as the attacker moved through a list of targets. “Successful calls often last between 10 and 15 minutes,” the researchers wrote.
Two paths into the network
Unit 42 documented two campaigns, both opening the same way and diverging at the point of malware delivery.

Full attack flow of the two Spring Ring campaigns (Source: Palo Alto Networks)
One campaign relied on the caller directing the victim to launch Quick Assist or download remote-support software, then requesting control of the machine. Once connected, the attacker ran commands to check the user’s group membership and domain, then downloaded an obfuscated PowerShell script that disabled Windows’ built-in malware scanning before contacting a command and control server.
The other campaign sent the victim a link to a file hosted on cloud storage, named to include their own company and username. Running the downloaded file triggered browser hijacking, scanning of the internal network over SMB, and an attempted Microsoft NT LAN Manager (NTLM) relay attack using a tool called PetitPotam.
The relay attempt aimed to get the organization’s domain controller to authenticate to a machine controlled by the attacker, a step that could grant domain-level privileges if it succeeded.
Both intrusion attempts were blocked by Unit 42 before the attackers reached their objective.
Collaboration platforms as a phishing channel
Phishing alerts tied to collaboration platforms accounted for 42% of all phishing alerts in Unit 42’s telemetry in the first four months of 2026, up from 30% in the preceding four months, the company said.
“By using seemingly legitimate external tenants and professional vishing lures, attackers can target hundreds of employees across many industries with minimal friction,” researchers warned.
“As these threats evolve, organizations must prioritize user education regarding unsolicited external communication across collaboration platforms.”
Palo Alto Networks published indicators of compromise, including the attacker-controlled domains, IP addresses, and file hashes, alongside the report.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/01/spring-ring-vishing-campaign-microsoft-teams/