Example of a Cortex alert on the creation of a suspicious chat in Microsoft Teams | Image: Unit 42
At a glance
| Actor or group | Unidentified attackers |
| Activity type | Voice phishing via Microsoft Teams |
| Targets or victims | Over 150 employees across 10+ companies |
| Scale | Widespread corporate targeting |
| Law-enforcement status | Active security investigation |
| Source | Palo Alto Networks Unit 42, KnowBe4 |
Cybercriminals targeted more than 150 employees using malicious Microsoft Teams chats between January and April 2026. Security researchers discovered a new operation called the Spring Ring vishing campaign. Attackers masqueraded as corporate IT help desk staff to deceive victims. They used these trusted communication channels to bypass standard email filters. This tactic signals a major shift in modern social engineering.
The Spring Ring vishing campaign represents a coordinated attack against corporate collaboration platforms. Attackers use external Microsoft Teams accounts to initiate direct contact. They impersonate trusted IT support personnel during live voice calls. “What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware,” the report explains. Consequently, the operation turns a safe workplace tool into a dangerous attack vector.
How Microsoft Teams Phishing Works
This Microsoft Teams phishing operation begins with a simple chat request. The threat actors create deceptive identities using the external.onmicrosoft.com naming format. They often choose professional display names like “Help Desk” or “IT Support.” Specifically, they use domain names such as “InternalSystemsDaily” or “MandatoryNetworkMonitoring” to project authority. These spoofed tenants resemble legitimate corporate infrastructure. Next, the attacker initiates an audio call with the targeted employee.
They cycle through targets rapidly. Many calls last only a few seconds or result in voicemails. However, successful calls often last between 10 and 15 minutes. The human element makes these attacks highly convincing. A professional voice on an audio call creates strong trust. Employees often lower their guard during direct voice interactions. The attacker then guides the victim to grant remote access. Alternatively, they convince the target to download custom malware files. Voice calls remain less monitored than standard corporate emails. This lack of oversight provides attackers with a secluded environment.
Technical Execution and Malware Delivery
Once the attacker gains trust, the attack chain diverges into two distinct paths. In the first method, attackers instruct victims to run legitimate support tools. They often utilize built-in Windows applications like Quick Assist. After gaining remote control, they run basic system enumeration commands. They check group memberships and domain details. Finally, they download an obfuscated remote access Trojan to maintain access. This specific malware disables the Antimalware Scan Interface. It modifies the system flags to bypass automated security checks. It then encrypts host data and beacons out to an external server.
The second method uses a highly tailored delivery approach. The attacker directs the employee to a customized cloud storage URL. This link usually contains the targeted company’s name. Clicking the link downloads a dangerous executable file. This file then triggers a sequence of browser hijacking and lateral movement. The executable moves itself into temporary directories to hide. It also launches a hidden Microsoft Edge instance and sideloads a malicious extension. During this advanced phase, attackers use Python scripts to scan internal networks. They generate authentication traffic directed at the organization’s domain controller. The attackers then attempt an NTLM relay attack using open-source tools. A successful relay attack could grant them full domain privileges.
Who Is Behind the Attacks
The exact individuals behind this Microsoft Teams phishing operation remain unidentified. Security teams suspect that organized cybercriminals run these campaigns. Similar past operations involved known advanced persistent threat groups. Previous campaigns focused heavily on credential harvesting via group chats. However, researchers have not officially attributed this specific activity to a named state actor. The perpetrators allegedly use commercial VPN services to hide their true locations.
These attackers possess strong social engineering skills. They execute their plans rapidly across multiple targeted organizations. Furthermore, they adapt their scripts based on the victim’s responses. They exploit the trust gap rather than relying on software exploits.
Analyzing the Scale and Impact
The scope of the Spring Ring vishing campaign is substantial. Threat actors targeted at least 10 different corporate tenants across various industries. They approached more than 150 individual employees during the observation period. Their persistence indicates a well-planned and scalable operation.
Collaboration tool abuse is rising sharply. According to a KnowBe4 report, Teams-based attacks increased by 41% recently. This surge stems from attackers exploiting default settings. Specifically, they abuse the feature that allows direct chats with anyone outside the organization. Additionally, phishing alerts from collaboration tools represented 42% of all Cortex alerts early this year. This marks a significant jump from previous months. Threat actors realize that email defenses are improving rapidly. Modern email gateways use advanced algorithms to block malicious links. Therefore, they now focus their efforts on less protected communication platforms.
What Comes Next and How to Stay Protected
The Spring Ring vishing campaign highlights major flaws in enterprise identity verification. SaaS applications hold critical data but often lack strict external communication controls. Attackers will likely refine their Microsoft Teams phishing techniques further. They will attempt to steal sensitive workflows and communication logs. As email security tightens, collaboration platforms will see more hostile activity.
Organizations must adapt their defenses immediately. First, administrators should restrict external communication paths within Microsoft Teams. They should limit unsolicited chats from outside domains whenever possible. Secondly, companies need to define strict, verifiable IT support processes. Employees must know how to verify unexpected support requests.
Finally, organizations must increase behavioral monitoring for identity anomalies. Security teams should flag rapid transitions from new external chats to voice calls. They should also monitor for atypical execution of remote management tools. Educating users about voice phishing dangers is now absolutely critical for corporate security.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!