Press play to start listening
A Teams message from “IT support” can be the start of a cyberattack. Cybersecurity researchers at Palo Alto Networks’ Unit 42 identified a voice-phishing campaign named Spring Ring, in which attackers posed as corporate support staff and used live Teams calls to persuade employees to run remote-access tools or malware.
According to researchers, between January and April 2026, the campaign targeted more than 150 employees across more than 10 organisations worldwide.
How the attack works
The attackers created external Microsoft Teams accounts through .onmicrosoft.com tenants they controlled. Unit 42 initially identified 26 distinct identities using display names such as “help desk” and “IT assistance.” Some accounts used the names of real industry professionals to appear credible, but Unit 42 found no evidence that those people’s accounts or Microsoft’s products had been compromised.
The callers wanted victims to hand over control of their computers. Posing as IT staff, they guided employees through opening Quick Assist or downloading another remote monitoring and management tool. After remote control was granted, the attackers ran commands including whoami /groups and net group /dom to inspect the user’s privileges and domain.
They then used PowerShell to download an obfuscated RAT. The malware included a nine-line command-and-control stager that disabled the Antimalware Scan Interface (AMSI) before contacting attacker-controlled infrastructure for additional payloads. Cortex XDR blocked the campaign during malware execution.
A second version of the attack used executables whose filenames and download locations were tailored to the targeted company and employee. Once opened, the malware moved itself to a temporary folder, created copies for persistence, launched Microsoft Edge without a visible window, and sideloaded a malicious browser extension. It then used Python to scan internal systems over port 445.
The attackers later attempted to use PetitPotam to coerce a domain controller into authenticating to a system they controlled. The resulting NTLM relay attack was designed to obtain domain-level privileges, but Unit 42’s managed detection and response service blocked the takeover attempt.
Teams Becomes a Phishing Target
Attackers are increasingly using Teams as a phishing channel. Palo Alto Networks noted that alerts from collaboration tools accounted for 42% of phishing alerts seen by Cortex during the first four months of 2026, up from 30% in the previous four months. KnowBe4 separately reported a 41% increase in Teams-based attacks between October 2025 and March 2026.
The same approach has appeared in other campaigns. In July, Sophos reported STAC4749, in which attackers used Teams calls and remote-access software to target dozens of North American organizations. At least three of those compromises resulted in the deployment of the Chaos ransomware.
The campaign also shows why recognising social engineering requires more than checking suspicious emails. Darktrace recently reported that 80% of US office workers surveyed were confident they could spot phishing during their daily work, but only 32% confidently identified an actual phishing email during testing. That confidence gap also applies when employees must assess an unexpected caller posing as IT support.
Experts Assess the Campaign
Cybersecurity executives who reviewed the findings told Hackread.com that Spring Ring relied on impersonation and employee trust, rather than a vulnerability in Microsoft Teams.
“Spring Ring did not exploit a vulnerability in Microsoft Teams. The attackers persuaded employees to launch legitimate remote-support tools or execute software and then transitioned into malware delivery and an attempted identity attack,” said Mika Aalto, co-founder and CEO of Hoxhunt.
Aalto also argued that employees need practical experience dealing with these calls, stating, “You cannot teach someone to handle vishing by showing them a slide about suspicious phone calls; at some point, the phone needs to ring.”
Aviv Nahum, co-founder and CEO of Above Security, said employees should independently verify the identity of anyone contacting them: “The security model therefore must move from ‘does this look real?’ to ‘can I independently verify that this person is who they claim to be?”

