A newly disclosed social engineering operation has weaponized one of the workplace’s most trusted tools, the voice call, to breach corporate networks without ever writing a line of exploit code.
Dubbed Spring Ring by researchers at Unit 42, the campaign shows how attackers are shifting from clickable phishing links to live, human-driven deception inside Microsoft Teams.
Between January and April 2026, Unit 42 tracked a coordinated vishing (voice phishing) operation that used external Microsoft Teams accounts to impersonate internal IT support staff. More than 150 employees across at least 10 companies in multiple industries were targeted.
Spring Ring Vishing

The attackers created chat requests using lookalike identity names such as “IT Help Desk” or “Support Staff,” operating out of throwaway .onmicrosoft.com tenants such as InternalSystemsDaily and ITProtectionDepartment, designed to mimic legitimate corporate infrastructure.
Once a chat connection was accepted, the attacker escalated to a live audio call, exploiting the instinctive trust employees place in a professional-sounding voice claiming to be their own tech support. Researchers documented two distinct technical paths stemming from the same vishing hook.
In “Campaign A,” attackers talked victims into launching legitimate remote monitoring tools like Windows Quick Assist, then used basic enumeration commands before deploying an obfuscated PowerShell-based remote access trojan that disabled Windows’ Antimalware Scan Interface and beaconed to a command-and-control domain.
“Campaign B” was far more tailored. Victims were guided to cloud-hosted executables named after their own company and username, hosted on Amazon S3 buckets.
The resulting malware spawned persistence copies, sideloaded a malicious extension into a headless Microsoft Edge instance, and then pivoted to lateral movement scanning internal servers over SMB and attempting a PetitPotam-based NTLM relay attack against the organization’s domain controller.
This isn’t an isolated technique. Unit 42’s telemetry shows phishing alerts originating from collaboration tools jumped from 30% to 42% of all phishing alerts in Cortex within just four months.
Separately, KnowBe4’s Phishing Threat Trends Report found that Teams-based attacks rose 41% between October 2025 and March 2026, largely by abusing Teams’ default “Chat with Anyone” feature, which allows external accounts to message employees directly.

Unlike earlier Teams-focused campaigns attributed to Russian state actor Cloaked Ursa (APT29), which relied on credential-harvesting links and fake tenants, Spring Ring’s operators lean almost entirely on live human interaction, a tactic that sidesteps automated link-scanning defenses and exploits a monitoring blind spot, since voice calls are rarely recorded or reviewed the way email and file activity are.
Unit 42 identifies several detection markers: a rapid chat-to-call transition, tenant names loaded with authority-signaling keywords such as “certified” or “infrastructure,” attacker IPs associated with commercial VPNs, and high-volume calling patterns in which a single identity cycles through five or six targets within minutes.
Post-compromise, defenders should flag unexpected RMM tool usage and access to unfamiliar cloud storage links. The core takeaway for security teams is straightforward: identity, not the network edge, is now the primary attack surface.
As collaboration platforms become repositories for sensitive workflows and communications, organizations need behavioral monitoring on chat and call metadata, not just email filters paired with employee training on unsolicited external contact, however credible the voice on the other end may sound.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.