Unveiling the Spring Ring Campaign: A Coordinated Phishing Operation Targeting Corporations
A recent report has shed light on a highly coordinated social-engineering campaign called "Spring Ring," which utilized external Microsoft Teams accounts to impersonate corporate IT help desk personnel. This operation has targeted over 150 employees across at least ten different organizations between January and April 2026. The sheer scale and sophistication of Spring Ring illustrate a significant shift in how cybercriminals are conducting phishing activities, moving away from traditional email scams and venturing into more trusted collaboration platforms.
Evolving Tactics: Voice Phishing Through Trusted Platforms
The attackers behind this campaign have demonstrated a notable trend: they are now leveraging platforms like Microsoft Teams to execute their phishing strategies. By employing live voice calls, they aim to persuade employees to run remote-access tools or inadvertently install malware on their systems. This innovative strategy shows attackers’ ability to adapt to changing security landscapes, as they exploit the inherent trust placed in collaboration tools.
The accounts used in the Spring Ring operation were set up on adversary-controlled .onmicrosoft[.]com tenants, which were cleverly disguised with names that echoed corporate terminology. Phrases such as "internal," "network," "certified," and "infrastructure" were employed to lend an air of credibility to the impersonators’ requests.
The Mechanics of an Attack
According to cybersecurity unit Unit 42, the operation was not the result of any inherent vulnerabilities or compromises within Microsoft Teams. Instead, it began with an unsolicited chat request through Teams. If the target accepted the request, the impersonator swiftly transitioned to a voice call, claiming to resolve an urgent technical issue. This component of “vishing,” or voice phishing, is central to their strategy, as real-time conversations allow attackers to overcome initial suspicions and adjust their approach based on the victim’s responses.
Attackers made persistent attempts to connect, often cycling through multiple employees. While some calls were cut short within seconds, others that progressed continued for significant periods, lasting from ten to 15 minutes. Such persistence highlights a growing trend wherein external collaboration features are being used as gateways for initial access to corporate networks.
Payload Delivery and System Compromise
Unit 42 observed distinct chains of payload delivery linked to the Teams vishing attempts. In one instance, the faux technician succeeded in persuading employees to either launch Windows Quick Assist or install legitimate remote monitoring and management tools. Once remote control was granted, attackers immediately initiated reconnaissance commands, using tools to gather information about the compromised system and its domain environment.
Subsequently, the attackers leveraged PowerShell to extract an obfuscated remote-access Trojan from a site named san-sid[.]com. Researchers noted that the attackers had created fictitious Microsoft 365 accounts to mimic internal support roles, adopting names like “IT Help Desk” and “Support Staff” to enhance the illusion of authenticity.
The malware employed in these attacks was designed to disable the Antimalware Scan Interface by manipulating flags, collect information about the host, and establish contact with command-and-control servers for additional payload instructions. Fortunately, defenses, such as Cortex XDR, successfully filtered out the malware during its execution.
The Broader Implications of the Spring Ring Campaign
Victims of the Spring Ring campaign were directed to download cloud-hosted executables that were misleadingly named to align with both the target organization and the individual recipient. Once activated, the malware established persistence within the system, creating additional executable copies and launching hidden browser instances to install stealthy extensions.
The attackers then engaged in internal system scanning and attempted to manipulate domain controller authentication to escalate their privileges within the organization’s network. However, defenses implemented by Unit 42 successfully thwarted these attempts at domain takeover.
A Growing Concern in SaaS Communications
The Spring Ring activity raises serious concerns about the reliability of Software as a Service (SaaS) communications. Employees often scrutinize external email communications for signs of phishing but may find it difficult to discern deception during a legitimate-looking Teams call, particularly when technical jargon is used to create an atmosphere of urgency.
Unit 42 reported that during the first quarter of 2026, phishing alerts derived from collaboration tools constituted 42% of all Cortex phishing alerts, a notable rise from 30% in the previous quarter. Additionally, data from KnowBe4 indicated a dramatic increase of 41% in Teams-based attacks between October 2025 and March 2026.
Recommendations for Organizations
Cybersecurity experts urge organizations to approach unsolicited external Teams communications, especially those that quickly transition into voice calls, as potential high-risk scenarios. Indicators of such fraudulent activity may include unusual patterns such as repeated short attempts to call from the same identity, unanticipated deployment of remote monitoring tools, and malicious Edge extensions.
To mitigate risks effectively, organizations should establish stringent controls over external Teams communications, mandate callback verification for IT service requests, and prohibit help desk staff from requesting installation of remote-access software through unsolicited communications. Continuous monitoring for signs of suspicious activity, including SMB scanning and forced authentications, is essential in maintaining security.
As organizations increasingly rely on collaboration tools, understanding and combating such sophisticated phishing campaigns becomes critical in safeguarding sensitive information and maintaining operational integrity.
