A new cyberattack campaign called Spring Ring is targeting Microsoft Teams users through voice phishing, also known as vishing. Researchers from Palo Alto Networks found that the campaign targeted at least 150 employees across multiple companies between January and April 2026. The attacks affected employees from at least 10 organizations and were designed to trick victims into giving attackers remote access to their computers. Instead of relying mainly on traditional email phishing, the attackers are using a trusted workplace platform to make their calls appear more believable.
The attacks usually begin with a Microsoft Teams chat where the attackers pretend to be members of the company’s IT or help-desk team. They use professional and urgent-looking names such as IT support, help desk or technical assistance to make the conversation seem genuine. After contacting an employee, the attackers start a voice call and claim that they need to fix a technical or security problem. They then guide the victim through steps that can give them remote control of the computer or allow malicious software to run.
Researchers found that the attackers were persistent and often made several attempts to reach their targets, including leaving voicemails when employees did not answer. Successful calls generally lasted around 10 to 15 minutes, giving attackers enough time to build trust and convince the victim to follow their instructions. In one attack method, victims were persuaded to use legitimate remote-access tools such as Windows Quick Assist or third-party remote monitoring and management software. Once access was obtained, the attackers carried out basic checks of the computer and network before attempting to install additional malware.
A more dangerous version of the attack was aimed beyond individual computers and attempted to reach an organization’s wider infrastructure. Attackers directed victims toward files stored in cloud services that appeared to be specific to the organization or user but were actually executable files. These files helped establish persistence, open a hidden Microsoft Edge session and load a malicious browser extension. The attackers then performed internal network reconnaissance and generated NTLM authentication traffic, eventually attempting a PetitPotam-based NTLM relay attack against a domain controller.
The attempted domain-level attack could have allowed the attackers to move much deeper into the organization if it had succeeded. Palo Alto Networks said its Unit 42 managed detection service blocked the attempted takeover before it could reach that stage. The campaign also reflects a wider rise in vishing attacks, with other security research reporting that voice-based attacks increased significantly during the first half of 2026. Similar Microsoft Teams campaigns have also been reported in recent months, showing that attackers are increasingly abusing workplace communication platforms to impersonate IT support and gain access to company systems.
Security researchers say organizations need to treat trusted collaboration platforms as possible entry points for cyberattacks rather than assuming that internal-looking Teams messages are automatically safe. Employees should be especially careful when an unfamiliar person claiming to be IT support suddenly asks them to install software, provide remote access or follow unusual technical instructions. Traditional security awareness advice such as avoiding suspicious links is not enough because these attacks depend heavily on real-time social engineering and direct conversation. Organizations are also advised to strengthen behavioral monitoring and identity-based detection so suspicious activity can be identified before attackers move further through the network.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news