Microsoft Teams Under Attack: The “Spring Ring” Vishing Campaign Shows How Hackers Are Turning IT Support Into a Weapon

Listen to this Post

Featured Image

A New Kind of Workplace Threat

Microsoft Teams has become part of the daily infrastructure of modern businesses. Employees use it to speak with colleagues, contact IT departments, exchange files, join meetings, and solve technical problems. That trust is exactly what a new cyberattack campaign is exploiting.

The operation, identified by Palo Alto Networks researchers as “Spring Ring,” targeted at least 150 Microsoft Teams users across a minimum of 10 organizations between January and April. Instead of relying primarily on suspicious emails or obvious phishing links, attackers used Teams conversations and voice calls to impersonate legitimate IT support personnel.

The objective was far more serious than stealing a password.

Attackers attempted to convince employees to install remote-access software, execute malicious programs, and, in more advanced cases, help establish a path toward compromising an organization’s domain controller.

The Evolution of Phishing

Traditional phishing attacks often depend on a victim opening an email, clicking a malicious link, or entering credentials into a fake website.

Spring Ring changes the psychology of that interaction.

Rather than waiting for an employee to make a mistake, attackers actively engage with the victim through a real-time conversation. The victim can ask questions, hear a supposedly helpful technician, and receive step-by-step instructions.

That makes the attack feel much more legitimate.

Palo Alto Networks described this transition as a movement from a passive click-and-harvest approach toward real-time social engineering. The attacker is no longer simply presenting a malicious link and hoping someone clicks it. The attacker becomes part of the conversation.

Why Microsoft Teams Is an Attractive Target

Microsoft Teams carries an enormous amount of implicit trust inside organizations.

Employees generally expect an unexpected message from an unfamiliar person on a random social network to be suspicious. An unexpected Teams message, however, can look considerably more believable.

An attacker can present themselves using names such as Help Desk, IT Assistance, or Support Staff.

The psychological trick is simple but powerful.

The attacker does not need to convince the employee that they are a mysterious hacker. They only need to convince the employee that they are someone from the company’s technical-support department.

The Attack Starts With a Conversation

According to the research, Spring Ring attacks begin when attackers create Teams chats using identities designed to resemble legitimate internal support personnel.

The attackers then attempt to initiate a voice call.

This matters because a voice conversation creates a completely different social dynamic from an email. The attacker can react to hesitation, answer questions, create urgency, and continuously push the victim toward the next step.

Successful calls reportedly lasted approximately 10 to 15 minutes.

That is enough time to build artificial credibility and guide someone through a technical procedure they might otherwise question.

Persistence Makes the Campaign More Dangerous

The attackers did not simply call once and disappear.

Researchers observed repeated attempts to engage targeted employees. When victims did not answer, attackers could leave voicemails and attempt to establish contact again.

This persistence is an important part of the campaign.

A traditional phishing email can be ignored. A determined attacker who repeatedly contacts an employee while pretending to be internal support can create the impression that the issue is urgent and legitimate.

The longer the conversation continues, the more opportunities the attacker has to manipulate the target.

Attack Vector One: Legitimate Remote-Access Tools

One of the observed attack paths relied on legitimate remote-access capabilities.

Victims were persuaded to use Windows Quick Assist or third-party remote monitoring and management tools.

This is particularly dangerous because security teams cannot simply assume that every remote-access application is malicious.

The software itself may be legitimate.

The problem is who is controlling it and why.

Once the attacker receives remote access, they can begin inspecting the compromised system, searching for information about the host and organization, and attempting to establish a stronger foothold.

In the observed campaign, researchers saw the attacker perform basic host and domain reconnaissance before attempting to download an obfuscated PowerShell-based remote-access trojan.

Endpoint protection ultimately blocked that activity.

The Real Problem With RMM Abuse

Remote monitoring and management software is designed to help administrators.

That makes it an attractive weapon for social engineers.

If a victim installs malware, defenders may have a straightforward malicious executable to investigate. If a victim voluntarily installs a legitimate remote-management application, however, the activity can look much closer to normal IT operations.

This creates a dangerous gray area.

Security teams must therefore evaluate not only what software is running, but also why it was installed, who requested it, who is controlling it, and whether that activity matches the employee’s normal behavior.

Attack Vector Two: Going After the Infrastructure

The second observed attack path was significantly more ambitious.

Instead of stopping with an individual workstation, the attackers attempted to move deeper into the organization’s infrastructure.

Victims were directed toward organization- and user-specific files hosted in cloud infrastructure. Those files appeared to contain executables that established persistence, launched a hidden Microsoft Edge instance, and sideloaded an extension.

From there, the attackers performed internal reconnaissance and generated NTLM authentication traffic.

This transformed the operation from a workstation compromise attempt into an infrastructure-level threat.

The NTLM Relay Danger

One of the most concerning elements involved an attempted NTLM relay attack.

The attackers attempted to use a PetitPotam-related technique to coerce a domain controller into authenticating toward attacker-controlled infrastructure.

If such an attack succeeds under the right conditions, stolen or relayed authentication material can potentially be used to move deeper into an enterprise environment.

That is why domain controllers remain among the most valuable targets inside Windows-based corporate networks.

A compromised employee workstation can be a serious incident.

A compromised identity infrastructure can become an organizational catastrophe.

Why the Domain Controller Matters

A domain controller is effectively one of the central authorities of a Windows enterprise environment.

It helps manage identities, authentication, permissions, and access to resources.

This creates an important distinction between ordinary account compromise and identity-infrastructure compromise.

An attacker who steals one employee’s account may gain access to that employee’s resources.

An attacker who compromises critical identity infrastructure can potentially influence access across a much larger portion of the organization.

That is why the second Spring Ring attack path deserves particular attention from defenders.

Security Teams Blocked the Attempt

Palo Alto Networks reported that its Unit 42 managed detection service blocked the attempted takeover.

That outcome highlights an important defensive lesson.

Attackers do not necessarily need a sophisticated zero-day vulnerability to create enormous risk. They can combine legitimate software, social engineering, stolen trust, cloud-hosted files, authentication protocols, and existing enterprise infrastructure.

The attack chain can become sophisticated even when individual components appear ordinary.

Vishing Is Becoming More Important

Spring Ring also fits into a much broader trend.

According to the

Voice phishing has always existed, but modern enterprise collaboration platforms give attackers new places to conduct it.

Teams, Slack, Zoom, Google Workspace, and other business platforms are increasingly becoming part of the attack surface.

The important change is that attackers are moving toward environments where employees already expect to communicate.

Trust Has Become the Attack Surface

The most interesting aspect of Spring Ring is not the malware.

It is trust.

The attacker is effectively borrowing the

The victim sees a familiar-looking business environment. The attacker uses a professional job title. The conversation sounds technical. The request may involve a legitimate application.

Everything surrounding the attack is designed to reduce suspicion.

That makes the campaign a strong example of how cybersecurity is increasingly becoming an identity problem rather than simply a malware problem.

The Help Desk Can Become the “Master Key”

Security experts quoted in the original report compared this approach to attacking the locksmith rather than breaking into an individual building.

The analogy is useful.

Organizations have spent years improving authentication, endpoint protection, email filtering, and network defenses. But if an attacker can impersonate someone who is authorized to administer systems, many of those defenses can be bypassed through human trust.

The help desk therefore deserves the same security attention as other privileged infrastructure.

Why Traditional Security Training Is Not Enough

Many security-awareness programs teach employees a simple formula:

Do not click suspicious links.

That advice remains useful, but Spring Ring demonstrates its limitations.

There may be no suspicious email.

There may be no obvious malicious link.

The attacker might call directly through a trusted business platform.

The employee may even be looking at legitimate software.

The dangerous instruction could simply be:

“Please install this tool so I can fix your computer.”

That is why awareness training needs to include realistic social-engineering scenarios rather than only generic phishing examples.

Employees Need a Different Question

Instead of asking only:

“Does this message look legitimate?”

Employees should also ask:

“Would my

That distinction is critical.

An unfamiliar person asking for remote access should trigger suspicion even if they appear inside the company’s collaboration platform.

An employee should independently verify unusual technical requests through a known internal channel.

Verification Should Happen Outside the Conversation

One of the strongest defenses against vishing is independent verification.

If someone claiming to be IT requests remote access, the employee should avoid using the contact information provided by that person.

Instead, the employee can contact the

The goal is to break the

Organizations Need Behavioral Monitoring

Palo Alto Networks also recommended stronger behavioral monitoring.

This is increasingly important because modern attacks can use legitimate tools.

Security systems should look for unusual combinations of activity, such as:

A user suddenly installing remote-management software.

An employee receiving unexpected external Teams calls.

New PowerShell activity after remote-access software installation.

Unusual authentication traffic.

Suspicious NTLM activity.

Unexpected domain reconnaissance.

Browser extensions appearing without normal administrative processes.

Executables launched from unusual cloud locations.

Authentication requests involving unfamiliar infrastructure.

Individually, some of these events may be harmless.

Together, they can tell a very different story.

Deep Analysis

Monitoring PowerShell Activity

Security teams can review PowerShell operational logs for unusual execution patterns:

Get-WinEvent -LogName "Microsoft-Windows-PowerShell/Operational" -MaxEvents 100 |
Select-Object TimeCreated, Id, Message

This does not automatically identify Spring Ring activity, but it can help investigators identify suspicious PowerShell execution following a remote-support incident.

Checking Installed Remote-Access Software

Administrators can inventory installed applications with:

Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\ |
Select-Object DisplayName, DisplayVersion, Publisher

A similar check can be performed against the 32-bit software registry location:

Get-ItemProperty HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ |
Select-Object DisplayName, DisplayVersion, Publisher

The objective is not to remove every RMM application.

The objective is to identify software that was installed unexpectedly or outside established IT procedures.

Reviewing Running Processes

During an investigation, defenders can examine active processes:

Get-Process |
Sort-Object CPU -Descending |
Select-Object -First 30 Name, Id, CPU

This can provide a quick overview of unusually active processes.

Process information should always be correlated with endpoint telemetry rather than treated as proof of compromise.

Reviewing Network Connections

Investigators can inspect active TCP connections with:

Get-NetTCPConnection -State Established |
Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,OwningProcess

Suspicious remote connections should then be correlated with the owning process and known enterprise infrastructure.

Checking Windows Event Logs

A basic event-log review can help investigators establish a timeline:

Get-WinEvent -FilterHashtable @{
LogName='Security'
StartTime=(Get-Date).AddHours(-24)
} -MaxEvents 200

For a serious incident, centralized SIEM telemetry should be preferred over relying exclusively on the local machine.

Reviewing PowerShell Script Block Logging

Where appropriate logging is enabled, defenders can search for PowerShell script-block activity:

Get-WinEvent -FilterHashtable @{
LogName='Microsoft-Windows-PowerShell/Operational'
Id=4104
} -MaxEvents 100

Event ID 4104 can provide useful evidence about executed PowerShell script blocks.

Checking Suspicious Scheduled Tasks

Persistence mechanisms should also be reviewed:

Get-ScheduledTask |
Where-Object {$_.State -ne "Disabled"} |
Select-Object TaskName, TaskPath, State

Unexpected scheduled tasks should be investigated alongside their executable paths and creation times.

Investigating Browser Extensions

Because the reported campaign involved browser activity and extension sideloading, organizations should monitor browser-extension installations.

A newly appearing extension on a workstation that has simultaneously experienced an unsolicited IT-support call should receive additional scrutiny.

The important point is correlation.

A browser extension by itself does not prove compromise.

A browser extension appearing immediately after a suspicious support interaction is considerably more interesting.

Protecting NTLM

Organizations should evaluate whether NTLM remains necessary across their environments.

Where operationally possible, reducing NTLM exposure can limit the opportunities available to relay-based attacks.

Defenders should also monitor authentication flows for unusual NTLM activity and investigate unexpected authentication requests involving domain controllers.

Protecting Domain Controllers

Domain controllers deserve additional monitoring because they represent a high-value identity target.

Security teams should closely monitor:

Authentication anomalies

Unusual machine-account activity

Unexpected NTLM authentication

Suspicious SMB activity

LDAP anomalies

Abnormal administrative logons

Unexpected service creation

Unusual PowerShell activity

The objective is to detect movement toward identity infrastructure before an attacker reaches domain-level control.

Teams Governance Matters

Organizations should also review Microsoft Teams configuration and governance.

Important questions include:

Can external users initiate unexpected conversations?

Can external accounts call employees?

How are external identities displayed?

Are employees clearly warned about external contacts?

Can employees report suspicious Teams conversations easily?

Are external file transfers monitored?

Are unusual collaboration patterns logged?

Security controls should extend beyond email.

Build a Vishing Playbook

Organizations should create a dedicated response procedure for suspected vishing.

Employees should know exactly what to do when someone claiming to be IT requests remote access.

The procedure can be simple:

Stop.

Do not install anything.

Do not provide remote control.

End the call.

Contact IT independently.

Report the incident.

Simple procedures are more likely to be followed under pressure.

What Undercode Say:

The Biggest Change Is Psychological

Spring Ring demonstrates that modern attackers increasingly understand that compromising humans can be easier than defeating security software.

Teams Is Not Automatically Safe

A message appearing inside a trusted collaboration platform should never receive an automatic trust pass.

Legitimate Software Can Become a Weapon

Quick Assist and RMM applications can be perfectly legitimate while still becoming dangerous when controlled by an unauthorized person.

Social Engineering Is Becoming More Interactive

Voice calls allow attackers to respond immediately to hesitation, objections, and questions.

Real-Time Manipulation Is Powerful

A ten-minute conversation gives an attacker substantially more influence than a static phishing email.

IT Support Is a Valuable Target

Employees are conditioned to cooperate with technical-support personnel, making help-desk impersonation especially effective.

Urgency Is a Red Flag

Attackers frequently use urgency to discourage independent verification.

Professional Language Can Be Deceptive

A polished support identity does not prove that the person behind it is legitimate.

Identity Is Becoming the New Perimeter

Traditional network boundaries matter less when attackers can manipulate users inside trusted SaaS environments.

RMM Tools Need Context

Security teams should distinguish between authorized administrative use and unexpected remote-access activity.

User Education Must Become Scenario-Based

Employees need to practice realistic attacks rather than memorize generic anti-phishing slogans.

Verification Should Be Independent

The person requesting access should never be the only source used to verify that access is legitimate.

Collaboration Platforms Need Security Monitoring

Teams activity should be incorporated into broader detection and response strategies.

Cloud Files Can Become Attack Infrastructure

Cloud-hosted executables can appear legitimate while providing attackers with another delivery mechanism.

Browser Extensions Deserve Attention

Unexpected extension installation can become an important signal during an investigation.

PowerShell Remains Valuable to Attackers

Even when an initial attack relies on social engineering, PowerShell can become useful for post-compromise activity.

Domain Controllers Remain High-Value Targets

Compromising identity infrastructure can have consequences far beyond a single endpoint.

NTLM Relay Risks Should Not Be Ignored

Organizations still depending on NTLM should carefully evaluate relay exposure and possible mitigation strategies.

Detection Must Connect Events

A Teams call, RMM installation, PowerShell execution, and suspicious authentication may look unrelated individually.

Together They Can Reveal the Attack Chain

Modern detection increasingly depends on behavioral correlation.

Endpoint Security Still Matters

The observed endpoint protection blocking the PowerShell RAT demonstrates why layered security remains valuable.

But Endpoint Protection Cannot Solve Everything

Security software cannot reliably stop an employee from voluntarily granting legitimate remote-access software control.

Humans Need Technical Guardrails

Training works best when combined with policies that restrict dangerous actions.

Privileged Workflows Need Strong Verification

Support processes that can lead to administrative access should receive additional authentication and authorization controls.

External Collaboration Should Be Treated Carefully

An external Teams identity should not automatically receive the same trust as an internal employee.

Attackers Are Following Convenience

Criminal groups naturally move toward platforms where victims already spend their working day.

SaaS Platforms Are Becoming Part of the Attack Surface

Communication systems contain identities, documents, workflows, and relationships that attackers can exploit.

Trust Relationships Can Be Abused

Attackers do not necessarily need to break

Help Desks Should Be Hardened

IT support teams should have documented procedures for remote-access requests and identity verification.

Remote Access Should Be Auditable

Every remote-control session should ideally have a clear reason, authorized user, approved tool, and audit trail.

Security Awareness Should Trigger Suspicion at the Right Moment

The goal is not to make employees distrust IT.

The goal is to teach them when trust should pause.

Vishing Detection Will Become More Important

As voice-based attacks increase, organizations will need better reporting and monitoring for suspicious calls.

Attackers Will Likely Automate More of This

AI can potentially help criminals create convincing scripts, personas, support terminology, and highly targeted conversations.

The Human Element Will Remain Critical

Even highly automated attacks often depend on convincing someone to perform one important action.

Defense Must Become Behavioral

Organizations need to understand what normal employee activity looks like and detect meaningful deviations.

The Most Dangerous Attack May Look Completely Normal

That is the central lesson of Spring Ring.

A familiar platform, a professional-looking support identity, and legitimate software can combine into an extremely dangerous attack chain.

✅ Spring Ring Targeted Microsoft Teams Users

The reported campaign targeted at least 150 users across at least 10 organizations between January and April. Palo Alto Networks researchers identified the operation and documented its use of Teams-based vishing.

The campaign was therefore not simply a theoretical attack concept, but an observed threat activity.

✅ Attackers Used Legitimate Remote-Access Tools

Researchers observed attackers directing victims toward Windows Quick Assist and third-party RMM software. The use of legitimate tools is particularly significant because it can complicate conventional malware detection.

The malicious element is the unauthorized control and social engineering surrounding the software.

✅ The Campaign Attempted NTLM Relay Activity

The reported advanced attack path included an attempted PetitPotam-related NTLM relay attack targeting authentication involving a domain controller.

Researchers said the attempted takeover was blocked by Unit 42’s managed detection service.

❌ Teams Communication Should Not Be Assumed Safe

Being contacted through Microsoft Teams does not prove that the sender is trustworthy.

Attackers are increasingly abusing trusted collaboration platforms precisely because employees are less suspicious of them than conventional phishing channels.

Prediction

(+1) Vishing Will Become More Common Inside Collaboration Platforms

Attackers are likely to continue moving beyond email as employees become more familiar with traditional phishing defenses.

Teams, Slack, Zoom, Google Workspace, and similar platforms could increasingly become environments for social engineering.

(+1) Help-Desk Impersonation Will Grow

Technical-support impersonation is particularly attractive because victims are conditioned to cooperate with people who claim to be solving computer problems.

Future campaigns may combine voice calls, fake support tickets, messaging platforms, and remote-access software.

(+1) Behavioral Security Will Become More Important

Organizations will increasingly rely on behavioral analytics to identify unusual combinations of legitimate activity.

A remote-access installation immediately followed by PowerShell execution and abnormal authentication activity could become a high-confidence detection pattern.

(-1) Traditional “Don’t Click Links” Training Will Become Less Effective

Awareness programs focused almost entirely on suspicious URLs and email senders will struggle against attacks that involve conversations rather than links.

Security education will need to evolve toward realistic scenarios involving calls, remote-access requests, cloud files, and identity verification.

(-1) Trusting Internal-Looking Accounts Will Become Riskier

An account that looks like “IT Support” or “Help Desk” cannot be trusted simply because the name appears professional.

Identity verification will increasingly need to happen independently of the communication channel.

(+1) Zero-Trust Principles Will Expand Into Collaboration Tools

The future of enterprise security will increasingly assume that users, devices, applications, and communication channels can be compromised.

Teams may remain essential to business operations, but trust in the platform itself will no longer be enough.

(+1) Identity Infrastructure Will Receive Greater Protection

The Spring Ring attempt against a domain controller illustrates why identity systems are among the most strategically important assets in an enterprise.

Organizations that strengthen authentication, reduce unnecessary NTLM exposure, monitor privileged activity, and aggressively protect domain controllers will be better positioned against the next generation of vishing attacks.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube