Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

By George Bailey   Published: 08/31/26   Updated: 08/31/26   2 min read
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

What Unit 42 Observed

Palo Alto Unit 42 says the Spring Ring campaign targeted more than 150 employees across at least 10 companies between January and April 2026 by abusing external Microsoft Teams accounts that impersonated internal help-desk staff.

The social engineering did not stop at chat messages. Operators used voice phishing to pressure users into handing over access through remote management tools or custom malware, turning routine collaboration into a delivery path for real intrusion activity.

Why The Teams Angle Matters

Security teams still tend to model email as the default phishing lane and Teams as a lower-risk collaboration space. That assumption is getting old fast. When a Teams identity looks familiar enough and the voice follow-up feels like ordinary support, the attack bypasses some of the suspicion users still reserve for email.

The campaign also matters because it shows attackers chaining trust across channels. Chat establishes legitimacy, voice creates urgency, and remote access or malware does the rest.

The Higher-Gravity Detail

Unit 42 describes a more advanced variant that moved into NTLM relay activity targeting domain controllers. That changes the story from endpoint nuisance to identity and control-plane risk.

Once collaboration abuse becomes a stepping stone into authentication infrastructure, the real question is no longer whether users were fooled. It is whether identity protections, remote support controls, and privileged-path monitoring can interrupt the intrusion before it stabilizes.

What Teams Should Do Next

Treat collaboration-tool trust as part of identity defense, not a separate awareness problem.

Source Context

CyberExperts used Palo Alto Unit 42 as the primary source for this article and preserved the details that matter most operationally: the scale of targeting, the Teams impersonation method, the voice-phishing pressure, and the NTLM relay escalation path aimed at domain controllers.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading