An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies. Adversaries initiated voice phishing calls to coerce victims into executing remote monitoring and management tools or custom malware. In advanced variants, attackers transitioned from vishing to NTLM relay attacks targeting domain controllers. Two distinct campaigns were observed: Campaign A utilized RMM tools and obfuscated PowerShell-based RATs, while Campaign B employed tailored cloud infrastructure with PetitPotam exploitation for domain-level compromise. The operation demonstrates the weaponization of trusted collaboration platforms as primary attack vectors, exploiting the trust gap in SaaS applications.
Indicators of Compromise
- ip: 5.181.3.106
- ip: 178.130.47.46
- ip: 80.66.72.215
- ip: 185.155.99.161
- ip: 45.8.157.185
- ip: 2.56.172.214
- ip: 185.234.67.53
- ip: 136.0.20.6
- ip: 92.118.232.131
- ip: 45.182.189.80
- domain: san-sid.com
- hash: 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b
An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Description
Between January and April 2026, a coordinated social engineering operation named Spring Ring leveraged external Microsoft Teams accounts to impersonate IT help desk personnel, targeting over 150 employees across at least 10 companies. Adversaries initiated voice phishing calls to coerce victims into executing remote monitoring and management tools or custom malware. In advanced variants, attackers transitioned from vishing to NTLM relay attacks targeting domain controllers. Two distinct campaigns were observed: Campaign A utilized RMM tools and obfuscated PowerShell-based RATs, while Campaign B employed tailored cloud infrastructure with PetitPotam exploitation for domain-level compromise. The operation demonstrates the weaponization of trusted collaboration platforms as primary attack vectors, exploiting the trust gap in SaaS applications.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/"]
- Adversary
- null
- Pulse Id
- 6a95603cd2ee92923d1e1dff
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip5.181.3.106 | — | |
ip178.130.47.46 | — | |
ip80.66.72.215 | — | |
ip185.155.99.161 | — | |
ip45.8.157.185 | — | |
ip2.56.172.214 | — | |
ip185.234.67.53 | — | |
ip136.0.20.6 | — | |
ip92.118.232.131 | — | |
ip45.182.189.80 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainsan-sid.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b | — |
Threat ID: 6a959fdfacd9273b49460448
Added to database: 08/31/2026, 15:38:07 UTC
Last updated: 09/01/2026, 01:23:56 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.