Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
ID: 034f033e-eeb2-5af5-903b-6f8612300e49
STIX ID: report--034f033e-eeb2-5af5-903b-6f8612300e49
Feed Name: Palo Alto Networks Unit 42
Between January and April 2026 Unit 42 tracked “Spring Ring,” a coordinated social-engineering campaign that used external Microsoft Teams accounts and live vishing to masquerade as internal IT and trick employees into running RMM tools or downloading tailored executables; two campaigns delivered an obfuscated PowerShell RAT and a bespoke Windows executable that implemented persistence, headless Edge extension sideloading, SMB scanning, NTLM authentication coercion and attempted a PetitPotam NTLM relay to gain domain-level privileges, with telemetry, IOCs (emails, IPs, a SHA256 hash and hosting URL), MITRE mappings and Palo Alto Networks mitigation recommendations included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
