Spring Ring: Voice Phishing Through Collaboration Tools
🛡️ Between January and April 2026, Unit 42 uncovered a coordinated vishing operation—named Spring Ring—using external Microsoft Teams accounts to impersonate IT help desk staff. The attackers contacted over 150 employees across at least 10 companies and employed live voice calls to coerce victims into installing RMM tools or custom malware. Two distinct campaigns were observed: one delivering an obfuscated PowerShell RAT and another using tailored executables that attempted NTLM relay attacks against domain controllers.
