TechNewsReel
Live

Spring Ring Operation Weaponizes Microsoft Teams via Vishing to Target Domain Controllers

Threat actors impersonated IT support in real-time voice calls to coerce employees into installing malware and facilitating NTLM relay attacks.

TechNewsReel Newsroom · September 2, 2026

A coordinated vishing operation dubbed "Spring Ring" targeted more than 150 employees across at least 10 organizations between January and April 2026. The campaign marks a sophisticated shift in social engineering, moving away from static email phishing toward real-time human engagement on trusted enterprise collaboration platforms.

According to reports from Dark Reading and Palo Alto Networks, attackers used external Microsoft Teams accounts to impersonate internal IT support and help desk personnel. These attackers utilized display names such as "help desk," "IT assistance," or "support staff" to establish immediate trust. Once a victim answered, the attackers engaged in voice phishing (vishing) calls that typically lasted between 10 and 15 minutes to coerce the target into compromising their own system.

The Attack Vectors

The operation employed two primary technical paths to gain a foothold. In the first vector, attackers leveraged legitimate remote monitoring and management (RMM) tools, such as Windows Quick Assist, to gain direct control of the victim's machine. In more advanced cases, the group deployed custom malware hosted on cloud infrastructure. This malware was designed to sideload Edge extensions and facilitate NTLM relay attacks.

Specifically, the group attempted PetitPotam-based NTLM relay attacks. This technique was used to coerce a domain controller into authenticating to infrastructure controlled by the attackers, potentially granting them administrative access to the organization's core identity management system.

A Shift in Social Engineering

This campaign reflects a broader trend where threat actors migrate from traditional "click-and-harvest" email models to SaaS-based collaboration tools. By integrating the attack into the Microsoft Teams workflow, the actors exploit the inherent trust users place in internal communication channels.

Noam Sala, a staff researcher at Palo Alto Networks, noted that the Spring Ring operation represents an evolution by merging vishing directly into the Teams workflow, transforming the attack into a real-time engagement rather than a passive interaction.

Industry Implications

By weaponizing the help desk workflow, attackers are no longer just targeting individual accounts; they are targeting the mechanisms of trust within an organization. Mika Aalto, co-founder and CEO at Hoxhunt, compared this strategy to targeting a locksmith rather than stealing a spare key, noting that controlling a help desk workflow can effectively generate a "master key" to unlock numerous systems across an enterprise.

This highlights a critical vulnerability in identity-based perimeters. It suggests that traditional security awareness training, which focuses heavily on "don't click the link," is insufficient against modern vishing threats that rely on verbal coercion and the impersonation of trusted internal authority figures.

What's Next

Organizations are now urged to implement stricter verification protocols for internal IT support requests and to monitor for unauthorized RMM tool usage. Security teams should specifically audit for PetitPotam-style authentication requests to domain controllers. As attackers continue to pivot toward real-time SaaS engagement, the industry must evolve its defense strategies to include voice-based authentication and more robust identity verification for internal support workflows.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.