Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC).
By comparing the two campaign paths, we can better understand the diversity of threats targeting collaboration platforms.
Previous Teams-based attacks, such as those by Cloaked Ursa (aka APT29 ), focused on credential harvesting and group chat-based social engineering. During the vishing call, the attacker directed the victim to a cloud endpoint. Our research into these campaigns highlights several consistent patterns: Our researchers were able to identify key markers of Spring Ring activity by analyzing the metadata of these interactions, despite the deceptive nature of the attacker’s initial lures: Upon a successful compromise, we observed endpoint activity characterized by: Organizations can identify the Spring Ring lifecycle before the attacker transitions from a chat to a domain-level attack, by profiling these signals, the origin of the tenant and the subsequent attack flow.
According to our recently published Insights blog , threat actors have increasingly moved away from traditional phishing techniques toward trusted collaboration tools. In the first four months of 2026, phishing alerts from collaboration tools represented 42% of all phishing alerts in Cortex, up from 30% of all phishing alerts in the preceding four months. Our investigation into this activity began after the release of a new detection suite for Microsoft Teams . The attack begins with creating a Microsoft Teams chat using identities designed to mirror legitimate internal support units.
This campaign was blocked by automated Cortex XDR Agent protections during the malware's execution phase. Robust behavioral monitoring can help identify identity-based anomalies before they escalate to lateral movement.
What changed
Spring Ring’s activity mirrors a broader trend in the threat landscape toward social engineering campaigns.
In addition, according to KnowBe4’s Phishing Threat Trends Report, Teams-based attacks rose by 41% [PDF] between October 2025 and March 2026.
Spring Ring’s approach relies on active human voice interaction.
Unlike email, where users are trained to look for external sender banners or suspicious links, communications platforms provide a closed loop that attackers exploit by: The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow.
The Spring Ring campaigns are a coordinated operation that relies on impersonating corporate IT structures.
Unit 42 has no evidence of any compromise or vulnerability within Microsoft's product related to this campaign.
Who is affected
They often relied on malicious links or fake Entra ID tenants to appear legitimate.
SaaS applications are essential for business operations, storing an organization’s most critical and sensitive data.
Figure 1 shows an example of the warning that Teams users get when an external identity creates a chat with them.
Attackers can drop their lures into a victim's primary communication channel using external Microsoft Teams accounts.
By monitoring these alerts, we identified a suspicious pattern of chat creation across multiple tenants.
To strengthen the impression of legitimacy, the attackers operate from external .onmicrosoft[.]com tenants.
Why this matters
By comparing the two campaign paths, we can better understand the diversity of threats targeting collaboration platforms.
The technical picture
Previous Teams-based attacks, such as those by Cloaked Ursa (aka APT29 ), focused on credential harvesting and group chat-based social engineering.
During the vishing call, the attacker directed the victim to a cloud endpoint.
Our research into these campaigns highlights several consistent patterns: Our researchers were able to identify key markers of Spring Ring activity by analyzing the metadata of these interactions, despite the deceptive nature of the attacker’s initial lures: Upon a successful compromise, we observed endpoint activity characterized by: Organizations can identify the Spring Ring lifecycle before the attacker transitions from a chat to a domain-level attack, by profiling these signals, the origin of the tenant and the subsequent attack flow.
How organizations are responding
According to our recently published Insights blog , threat actors have increasingly moved away from traditional phishing techniques toward trusted collaboration tools.
In the first four months of 2026, phishing alerts from collaboration tools represented 42% of all phishing alerts in Cortex, up from 30% of all phishing alerts in the preceding four months.
Our investigation into this activity began after the release of a new detection suite for Microsoft Teams .
The attack begins with creating a Microsoft Teams chat using identities designed to mirror legitimate internal support units.
They are used by attackers to provision Microsoft 365 tenants.
After the chat is created, the attacker initiates a voice call (the vishing element) to coerce the victim.
What defenders should do now
This campaign was blocked by automated Cortex XDR Agent protections during the malware's execution phase.
Robust behavioral monitoring can help identify identity-based anomalies before they escalate to lateral movement.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.