Actor Profile
Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel. The operation targeted more than 150 employees across at least 10 companies in various industries. Unlike traditional phishing campaigns, Spring Ring employs active voice phishing (vishing) techniques combined with real-time human interaction to manipulate victims into executing remote monitoring and management (RMM) tools or custom malware. In advanced variants, attackers pivot from vishing calls to NTLM relay attacks targeting organizational domain controllers. The campaign represents an evolution in collaboration platform abuse, exploiting the trust gap inherent in SaaS communication tools where users expect legitimate internal communications.
TTPs (Tactics, Techniques, Procedures)
Spring Ring employs social engineering as the primary attack vector (T1566 - Phishing), specifically leveraging trusted collaboration platforms. The campaign uses impersonation techniques with crafted personas and display names mimicking IT help desk staff. Attackers conduct voice phishing (vishing) calls to establish trust and manipulate victims in real-time. Initial access is achieved through external Microsoft Teams chat creation, exploiting the platform's "Chat with Anyone" feature. Payload delivery occurs via two distinct vectors: coercing victims to execute remote monitoring and management (RMM) tools or custom malware (T1204 - User Execution), and in advanced variants, pivoting to NTLM relay attacks (T1557 - Adversary-in-the-Middle) targeting domain controllers using tools like PetitPotam. The operation demonstrates credential access attempts and potential lateral movement to domain-level privileges.
Targets & Patterns
Spring Ring targets enterprise organizations across various industries, with telemetry revealing attacks against more than 150 employees at a minimum of 10 companies. The campaign specifically focuses on enterprise domain controllers as high-value targets for privilege escalation. Victims are selected based on their access to organizational SaaS collaboration platforms, particularly Microsoft Teams environments. The targeting pattern suggests adversaries seek employees who would reasonably interact with IT help desk personnel, making them susceptible to impersonation tactics. The campaign exploits the trust employees place in internal support structures and collaboration platforms, targeting the identity layer as the primary attack surface. The focus on domain controllers indicates intent to achieve domain-level privileges and establish persistent access to enterprise networks.
Historical Context
Spring Ring represents an evolution from previous Microsoft Teams-based attacks, notably those conducted by Cloaked Ursa (APT29), which focused on credential harvesting and group chat-based social engineering using malicious links or fake Entra ID tenants. Unlike these predecessor campaigns that relied on passive click-and-harvest models, Spring Ring introduces active human voice interaction and real-time engagement capabilities. The campaign aligns with broader threat landscape trends documented in early 2026, where phishing alerts from collaboration tools increased from 30% to 42% of all phishing alerts between late 2025 and early 2026. KnowBe4 research corroborates this trend, reporting a 41% increase in Teams-based attacks between October 2025 and March 2026. Spring Ring's discovery was enabled by new detection capabilities for Microsoft Teams released prior to the investigation period, highlighting the ongoing cat-and-mouse dynamic between defensive tooling and adversary tradecraft evolution.
Defensive Recommendations
- Monitor and alert on external Microsoft Teams chat creation events, particularly from newly created or suspicious external tenants, using Cortex XDR or XSIAM detection rules for collaboration platform abuse
- Implement organizational policies to disable or restrict the Microsoft Teams 'Chat with Anyone' feature, limiting external communication to approved domains and requiring administrative approval for external tenant interactions
- Deploy network-level protections against NTLM relay attacks targeting domain controllers, including enforcing SMB signing, disabling NTLM authentication where possible, and monitoring for PetitPotam exploitation attempts (CVE-2021-36942)
- Establish baseline monitoring for Remote Monitoring and Management (RMM) tool execution (T1204.002) via endpoint detection, flagging unauthorized RMM software installations and blocking execution outside approved change windows
- Conduct security awareness training focused on vishing techniques via collaboration platforms, emphasizing verification procedures for IT help desk contacts through out-of-band communication channels before executing any software or providing credentials
