
What Unit 42 Observed
Palo Alto Unit 42 says the Spring Ring campaign targeted more than 150 employees across at least 10 companies between January and April 2026 by abusing external Microsoft Teams accounts that impersonated internal help-desk staff.
The social engineering did not stop at chat messages. Operators used voice phishing to pressure users into handing over access through remote management tools or custom malware, turning routine collaboration into a delivery path for real intrusion activity.
Why The Teams Angle Matters
Security teams still tend to model email as the default phishing lane and Teams as a lower-risk collaboration space. That assumption is getting old fast. When a Teams identity looks familiar enough and the voice follow-up feels like ordinary support, the attack bypasses some of the suspicion users still reserve for email.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
The campaign also matters because it shows attackers chaining trust across channels. Chat establishes legitimacy, voice creates urgency, and remote access or malware does the rest.
The Higher-Gravity Detail
Unit 42 describes a more advanced variant that moved into NTLM relay activity targeting domain controllers. That changes the story from endpoint nuisance to identity and control-plane risk.
Once collaboration abuse becomes a stepping stone into authentication infrastructure, the real question is no longer whether users were fooled. It is whether identity protections, remote support controls, and privileged-path monitoring can interrupt the intrusion before it stabilizes.
What Teams Should Do Next
Treat collaboration-tool trust as part of identity defense, not a separate awareness problem.
- Review Microsoft Teams settings for external communication, suspicious new external contacts, and impersonation patterns that could make fake help-desk outreach look ordinary.
- Pressure-test remote support workflows so users have a clean way to verify urgent support requests before installing tools or approving access.
- Hunt for unusual remote-management launches, voice-phishing reports, and authentication activity that clusters around collaboration interactions.
- Make sure detections and logging cover NTLM relay-adjacent behavior and privileged authentication paths, especially near domain controllers.
- Brief help-desk, identity, and user-support teams together because this attack succeeds in the gaps between their responsibilities.
Source Context
CyberExperts used Palo Alto Unit 42 as the primary source for this article and preserved the details that matter most operationally: the scale of targeting, the Teams impersonation method, the voice-phishing pressure, and the NTLM relay escalation path aimed at domain controllers.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief