Spring Ring was a coordinated social engineering operation that used external Microsoft Teams accounts to impersonate IT help desk staff and lure more than 150 employees across at least 10 companies into vishing calls. The campaign led to attempts to deploy RMM tools, an obfuscated PowerShell RAT from san-sid[.]com, and in a second path, a PetitPotam-based NTLM relay attack against a domain controller. #SpringRing #PetitPotam #MicrosoftTeams #san-sidcom #Unit42
Keypoints
- Spring Ring is a coordinated campaign active from January to April 2026 that abused external Microsoft Teams accounts to pose as internal IT support.
- The operation targeted more than 150 employees across at least 10 companies in multiple industries.
- Attackers used vishing calls to build trust and push victims to run RMM tools or open malicious files.
- One campaign delivered an obfuscated PowerShell RAT from san-sid[.]com and used AMSI bypass techniques.
- A second campaign used tailored cloud-hosted executables and progressed to SMB scanning, NTLM traffic, and a PetitPotam NTLM relay attempt against a domain controller.
- Defenders can detect the activity through anomalous Teams chat-to-call behavior, suspicious external tenants, unusual process execution, and coercive authentication patterns.
- Palo Alto Networks states that Cortex XDR, XSIAM, and related products blocked or mitigated parts of the activity.
MITRE Techniques
- [T1566 ] Phishing â Used through external Microsoft Teams chats and link insertion to initiate the social engineering flow (âExternal user started a Microsoft Teams conversationâ, âExternal user added a link to a Microsoft Teams chatâ).
- [T1566.004 ] Phishing: Spearphishing Voice â Used when attackers followed the chat with voice calls to impersonate IT support and coerce victims (âExternal user call via Microsoft Teamsâ, âa voice phishing (vishing) callâ).
- [T1204 ] User Execution â Victims were instructed to launch tools or execute downloaded payloads (âguides targeted employees through the steps to grant them remote control or execute malicious payloadsâ).
- [T1567.002 ] Exfiltration Over Web Service: Exfiltration to Cloud Storage â The malware connected to a cloud resource as part of its payload activity (âA process connected to an atypical rare cloud resourceâ).
- [T1053 ] Scheduled Task/Job â Persistence included creation of an uncommon local scheduled task (âUncommon local scheduled task createdâ).
- [T1176.001 ] Software Extensions: Browser Extensions â The attackers forced a browser extension to load and sideloaded an Edge extension (âA browser was forced to load an extensionâ, âUncommon browser extension loadedâ).
- [T1046 ] Network Service Discovery â Used SMB scanning from a non-standard process to discover internal servers (âSMB scanning: Initiated port 445 traffic targeting internal serversâ).
- [T1550 ] Use Alternate Authentication Material â Used NTLM traffic to target the domain controller (âGenerated NTLM traffic targeting the organizationâs DCâ).
- [T1187 ] Forced Authentication â Attempted to coerce the domain controller into authenticating back using PetitPotam (âattempted a PetitPotam attack to coerce the DC into authenticating backâ).
- [T1557.001 ] Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay â The NTLM relay path was designed to relay coerced authentication and gain domain-level privileges (âNTLM relay attackâ).
Indicators of Compromise
- [Domains ] Malicious vishing identities and payload hosting â san-sid[.]com, hxxps[:]//san-sid[.]com/owners
- [File Hashes ] Obfuscated PowerShell RAT dropper from Campaign A â 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b
- [File Names ] Suspicious executables and persistence copies used in Campaign B â -org-filters-update-[.]exe, vhlp-*.exe, scnr-*.exe
- [Cloud URLs / Hosts ] Tailored download and staging infrastructure â -org-filters-update-.s3.us-west-2.amazonaws[.]com
- [Microsoft 365 / Teams Tenants ] External impersonation accounts used for vishing â helpdesk@itprotectiondepartment[.]onmicrosoft[.]com, ithelp@internalsystemsdaily[.]onmicrosoft[.]com, and other listed .onmicrosoft[.]com accounts
- [IP Addresses ] Proxy/VPN infrastructure used to obscure attacker origin â 193.32.248[.]251, 185.65.134[.]209, and 14 more IPs listed in the article
- [Scripts / Commands ] Host enumeration and payload execution artifacts â whoami /groups, net group /dom, Invoke-WebRequest, PowerShell-based RAT stager
Read more: https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/