# Spring Ring Voice Phishing Targets Microsoft Teams Users

> Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.

- Published: 2026-09-01T02:47:23.000Z
- Severity: medium
- Category: Threat Intel
- Tags: Microsoft Teams, Vishing, Social Engineering, NTLM Relay, Spring Ring
- Author: Runtime Rebel Intel
- Primary source: https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
- Canonical: https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users

## Key points

- Immediate impact: Spring Ring vishing targets Microsoft Teams users to deploy RMM tools or initiate NTLM relay attacks.
- Affected systems: Employees across various industries using Microsoft Teams are targeted via external accounts.
- Remediation: Enhance user awareness against vishing and implement strong authentication protocols for critical systems.

## Spring Ring: Voice [Phishing](/glossary#phishing) Campaigns Leveraging Microsoft Teams

The Spring Ring operation represents a sophisticated [social engineering](/glossary#social-engineering) campaign that weaponizes Microsoft Teams to execute voice phishing ([vishing](/glossary#vishing)) attacks. Active between January and April 2026, this coordinated effort has targeted over 150 employees across at least 10 companies in diverse sectors. The campaign deviates from traditional phishing by exploiting trusted collaboration platforms and relies on direct human interaction to bypass conventional security controls, as detailed by [Unit 42](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/).

### Technical Analysis of Spring Ring Voice Phishing Campaigns in Microsoft Teams

Threat actors behind Spring Ring initiate contact by creating external Microsoft Teams chats, often using professional, urgency-focused display names such as "help desk," "IT assistance," or "support staff." To enhance perceived legitimacy, attackers provision Microsoft 365 tenants using external .onmicrosoft[.]com domains, which mimic legitimate corporate infrastructure. In more advanced instances, they have even adopted specific names of legitimate industry personnel, adding a layer of authenticity to their impersonation.

Once a chat is established, the core of the attack unfolds as a vishing call. Attackers coerce victims into actions such as installing [remote monitoring and management (RMM)](/glossary#remote-monitoring-and-management-rmm) tools or custom [malware](/glossary#malware). A critical evolution in their methodology involves transitioning from a vishing call to a full-blown Microsoft NTLM relay attack aimed at an organization's domain controller. This advanced tactic, potentially leveraging tools like PetitPotam after establishing initial trust, highlights the campaign's potential for significant network compromise.

This approach signals a broader trend in the [threat landscape](/glossary#threat-landscape) where adversaries shift from traditional email-based phishing to collaboration platforms. According to Unit 42's insights, phishing alerts from collaboration tools surged to 42% of all phishing alerts in the first four months of 2026, up from 30% previously. This trend is further supported by a 41% rise in Teams-based attacks between October 2025 and March 2026, as noted by KnowBe4. Unlike prior Teams attacks, such as those by [APT29](https://en.wikipedia.org/wiki/APT29) (Cloaked Ursa) which focused on [credential harvesting](/glossary#credential-harvesting) via malicious links, Spring Ring leverages active voice interaction. This allows attackers to adapt their approach in real-time based on victim responses, exploiting the inherent trust users place in SaaS collaboration tools without requiring a software [vulnerability](/glossary#vulnerability).

### Mitigating NTLM Relay Attacks via Vishing and Teams Impersonation

Defending against sophisticated social engineering campaigns like Spring Ring requires a multi-layered approach focusing on both technical controls and user awareness. Security professionals looking to detect Microsoft Teams vishing and prevent successful exploitation should prioritize the following:

*   **User Awareness Training**: Conduct regular, targeted training on vishing tactics, specifically highlighting the risks of unsolicited calls and requests on collaboration platforms like Microsoft Teams. Emphasize verification procedures for IT support requests, regardless of the communication channel.
*   **Review External Communication Policies**: Stricten policies regarding external communications within Microsoft Teams. Consider limiting external chat capabilities or implementing clear visual indicators for external users to help employees identify non-internal contacts.
*   **Implement and Enforce Multi-Factor Authentication ([MFA](/glossary#mfa))**: Ensure MFA is enforced for all corporate accounts and critical systems. This acts as a crucial barrier even if credentials are inadvertently compromised through social engineering.
*   **Monitor for Unauthorized RMM Tool Installation**: Implement [endpoint](/glossary#endpoint) detection and response ([EDR](/glossary#edr)) solutions to monitor for and alert on the installation or execution of unauthorized remote monitoring and management tools.
*   **Harden Domain Controllers**: Implement NTLM relay attack mitigation strategies, such as enforcing SMB signing, enabling Extended Protection for Authentication (EPA), and disabling NTLM where possible, particularly for critical domain services. Regularly review configurations of domain controllers to protect against known NTLM relay vectors.
*   **Review Microsoft Teams Security Settings**: Periodically audit and adjust security settings within Microsoft Teams and Microsoft 365 to align with the organization's risk posture, especially concerning external collaboration and guest access.

**Related:** [ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO](/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso), [Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk](/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users
