Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team.

The campaign ran between January and April 2026 and reached more than 150 employees at more than 10 companies in different industries.

The attackers registered external Microsoft Teams tenants with names built to resemble internal IT departments, such as “ITProtectionDepartment” or “MandatoryNetworkMonitoring,” using the onmicrosoft.com format that Microsoft 365 customers normally use for their own organizations, Unit 42 found.

Some attackers used specific names, rather than generic titles like “help desk,” to increase the perceived authenticity of the technician on the other end of the line.

“Threat actors frequently abuse or subvert legitimate products for malicious purposes. This does not indicate that the product itself is flawed or compromised,” researchers noted.

Unit 42 identified 26 distinct attacker identities behind the chat and call attempts.

Once a chat was accepted, the attacker placed a call. Many attempts were missed or lasted only seconds, as the attacker moved through a list of targets. “Successful calls often last between 10 and 15 minutes,” the researchers wrote.

Two paths into the network

Unit 42 documented two campaigns, both opening the same way and diverging at the point of malware delivery.

Microsoft Teams vishing

Full attack flow of the two Spring Ring campaigns (Source: Palo Alto Networks)

One campaign relied on the caller directing the victim to launch Quick Assist or download remote-support software, then requesting control of the machine. Once connected, the attacker ran commands to check the user’s group membership and domain, then downloaded an obfuscated PowerShell script that disabled Windows’ built-in malware scanning before contacting a command and control server.

The other campaign sent the victim a link to a file hosted on cloud storage, named to include their own company and username. Running the downloaded file triggered browser hijacking, scanning of the internal network over SMB, and an attempted Microsoft NT LAN Manager (NTLM) relay attack using a tool called PetitPotam.

The relay attempt aimed to get the organization’s domain controller to authenticate to a machine controlled by the attacker, a step that could grant domain-level privileges if it succeeded.

Both intrusion attempts were blocked by Unit 42 before the attackers reached their objective.

Collaboration platforms as a phishing channel

Phishing alerts tied to collaboration platforms accounted for 42% of all phishing alerts in Unit 42’s telemetry in the first four months of 2026, up from 30% in the preceding four months, the company said.

“By using seemingly legitimate external tenants and professional vishing lures, attackers can target hundreds of employees across many industries with minimal friction,” researchers warned.

“As these threats evolve, organizations must prioritize user education regarding unsolicited external communication across collaboration platforms.”

Palo Alto Networks published indicators of compromise, including the attacker-controlled domains, IP addresses, and file hashes, alongside the report.

Don't miss