Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Spring Ring was a coordinated social engineering operation that used external Microsoft Teams accounts to impersonate IT help desk staff and lure more than 150 employees across at least 10 companies into vishing calls. The campaign led to attempts to deploy RMM tools, an obfuscated PowerShell RAT from san-sid[.]com, and in a second path, a PetitPotam-based NTLM relay attack against a domain controller. #SpringRing #PetitPotam #MicrosoftTeams #san-sidcom #Unit42

Keypoints

  • Spring Ring is a coordinated campaign active from January to April 2026 that abused external Microsoft Teams accounts to pose as internal IT support.
  • The operation targeted more than 150 employees across at least 10 companies in multiple industries.
  • Attackers used vishing calls to build trust and push victims to run RMM tools or open malicious files.
  • One campaign delivered an obfuscated PowerShell RAT from san-sid[.]com and used AMSI bypass techniques.
  • A second campaign used tailored cloud-hosted executables and progressed to SMB scanning, NTLM traffic, and a PetitPotam NTLM relay attempt against a domain controller.
  • Defenders can detect the activity through anomalous Teams chat-to-call behavior, suspicious external tenants, unusual process execution, and coercive authentication patterns.
  • Palo Alto Networks states that Cortex XDR, XSIAM, and related products blocked or mitigated parts of the activity.

MITRE Techniques

  • [T1566 ] Phishing – Used through external Microsoft Teams chats and link insertion to initiate the social engineering flow (‘External user started a Microsoft Teams conversation’, ‘External user added a link to a Microsoft Teams chat’).
  • [T1566.004 ] Phishing: Spearphishing Voice – Used when attackers followed the chat with voice calls to impersonate IT support and coerce victims (‘External user call via Microsoft Teams’, ‘a voice phishing (vishing) call’).
  • [T1204 ] User Execution – Victims were instructed to launch tools or execute downloaded payloads (‘guides targeted employees through the steps to grant them remote control or execute malicious payloads’).
  • [T1567.002 ] Exfiltration Over Web Service: Exfiltration to Cloud Storage – The malware connected to a cloud resource as part of its payload activity (‘A process connected to an atypical rare cloud resource’).
  • [T1053 ] Scheduled Task/Job – Persistence included creation of an uncommon local scheduled task (‘Uncommon local scheduled task created’).
  • [T1176.001 ] Software Extensions: Browser Extensions – The attackers forced a browser extension to load and sideloaded an Edge extension (‘A browser was forced to load an extension’, ‘Uncommon browser extension loaded’).
  • [T1046 ] Network Service Discovery – Used SMB scanning from a non-standard process to discover internal servers (‘SMB scanning: Initiated port 445 traffic targeting internal servers’).
  • [T1550 ] Use Alternate Authentication Material – Used NTLM traffic to target the domain controller (‘Generated NTLM traffic targeting the organization’s DC’).
  • [T1187 ] Forced Authentication – Attempted to coerce the domain controller into authenticating back using PetitPotam (‘attempted a PetitPotam attack to coerce the DC into authenticating back’).
  • [T1557.001 ] Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay – The NTLM relay path was designed to relay coerced authentication and gain domain-level privileges (‘NTLM relay attack’).

Indicators of Compromise

  • [Domains ] Malicious vishing identities and payload hosting – san-sid[.]com, hxxps[:]//san-sid[.]com/owners
  • [File Hashes ] Obfuscated PowerShell RAT dropper from Campaign A – 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b
  • [File Names ] Suspicious executables and persistence copies used in Campaign B – -org-filters-update-[.]exe, vhlp-*.exe, scnr-*.exe
  • [Cloud URLs / Hosts ] Tailored download and staging infrastructure – -org-filters-update-.s3.us-west-2.amazonaws[.]com
  • [Microsoft 365 / Teams Tenants ] External impersonation accounts used for vishing – helpdesk@itprotectiondepartment[.]onmicrosoft[.]com, ithelp@internalsystemsdaily[.]onmicrosoft[.]com, and other listed .onmicrosoft[.]com accounts
  • [IP Addresses ] Proxy/VPN infrastructure used to obscure attacker origin – 193.32.248[.]251, 185.65.134[.]209, and 14 more IPs listed in the article
  • [Scripts / Commands ] Host enumeration and payload execution artifacts – whoami /groups, net group /dom, Invoke-WebRequest, PowerShell-based RAT stager


Read more: https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/