Skip to main content
Emerging Threats

Microsoft Teams Targeted in Voice Phishing Campaigns

Person sits at cluttered desk, looking concerned while on video conference on computer with Microsoft Teams on screen.

"Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel," Unit 42 at Palo Alto Networks reported.

How Spring Ring worked: a voice-first lure inside Microsoft Teams

Unit 42 named the activity Spring Ring. Its telemetry shows attackers created Microsoft Teams chats from external .onmicrosoft[.]com tenants that mimicked internal help desks, then escalated quickly from chat to live voice calls. The operation targeted more than 150 employees across at least 10 organizations between January and April 2026. What looked like routine support messages were in many cases the opening move in a vishing sequence designed to coerce victims into granting remote access or running malware.

Two divergent technical paths: Campaign A and Campaign B

Unit 42 analyzed two observed campaigns that began with the same Teams-based voice lure but diverged in payload and post‑compromise behavior.

  • Campaign A: Attackers guided victims to execute legitimate remote monitoring and management (RMM) tools or Windows Quick Assist. After remote control, the adversary ran enumeration commands and used PowerShell to download an obfuscated RAT from san-sid[.]com. The obfuscated dropper (SHA256: 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b) disabled AMSI and staged a nine-line C2 stager that encrypted host data and beaconed to san-sid[.]com. Cortex XDR Agent protections blocked this execution phase.
  • Campaign B: During the vishing call, victims were directed to a cloud-hosted file tailored with their company and name (for example: <company_name>-org-filters-update-<victim_name>.s3.us-west-2.amazonaws[.]com). The downloaded executable persisted in \\Temp\\, spawned vhlp-*.exe and scnr-*.exe, sideloaded a Microsoft Edge extension, and used a bundled Python binary (C:\\ProgramData\\IntegrityData\\python.exe) to scan SMB (port 445) and generate NTLM traffic toward the domain controller. The attacker attempted a PetitPotam NTLM relay to coerce domain authentication; Unit 42 Managed Detection and Response blocked the domain-takeover attempt.

Indicators: attacker identities, infrastructure, and behavioral markers

Unit 42 published concrete indicators used by Spring Ring. Attackers frequently created identities with authoritative, urgency-focused display names and used .onmicrosoft[.]com tenants containing words like internal, certified, network or infrastructure. Examples of vishing identities include helpdesk@itprotectiondepartment[.]onmicrosoft[.]com and patrick[..]@infrastructureopsdesk.onmicrosoft[.]com. Infrastructure traced to commercial VPNs and proxies included IPs such as 193.32.248[.]251, 185.65.134[.]209, and 45.33.22[.]47.

Behavioral markers highlighted by Unit 42 that teams can monitor include a rapid chat-to-call transition, short "cycling" call attempts followed by longer 10–15 minute successful sessions, and multiple near-simultaneous approaches (5–6 spoofed identities within minutes). Post-compromise signals included atypical execution of RMM tools by users who do not require support and access to cloud-hosted URLs tailored to the victim.

Detection, mitigation, and where protections succeeded

Palo Alto Networks noted that automated protections and managed detection blocked both campaigns at critical stages. Cortex XDR Agent protections prevented the PowerShell RAT from executing in Campaign A, and Unit 42 Managed Detection and Response stopped the PetitPotam-based domain takeover in Campaign B. The report also lists detection and protection capabilities that identify known malicious domains and behavior — including Advanced URL Filtering, Advanced DNS Security, Cortex Cloud Identity Threat Detection, Idira Threat Detection and Response, and Idira Endpoint Privileged Manager.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: Prioritize behavioral telemetry for collaboration platforms—look for rapid chat-to-call escalation, onmicrosoft tenant origins, and unusual RMM execution. Use identity‑centric detection that can baseline normal chat and voice interactions.
  • Procurement and IT leaders: Treat external .onmicrosoft[.]com chats as a potential risk vector; ensure tooling can flag tenant origin and enforce verification for unsolicited remote support requests.
  • End users and help-desk managers: Train employees to refuse unsolicited Teams voice support and to verify support requests through established internal channels; watch for tailored cloud links that include company and user names.

Spring Ring illustrates a clear shift: collaboration platforms are not simply channels for credential-phishing links but can be the starting point for voice‑led coercion that escalates to domain-level attacks. Unit 42's telemetry shows these campaigns are scalable and human-led, mixing social engineering with open-source exploitation like PetitPotam. The central question left by the facts is operational: will defenders instrument chat and voice metadata as rigorously as email and endpoint telemetry to detect the small behavioral anomalies these attackers rely on?

https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/