Full research report
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Executive assessment
Spring Ring represents a maturation of the Teams-based social engineering threat, moving beyond the credential-harvesting link-drop techniques historically associated with state-aligned actors toward a model requiring live voice interaction—deliberately bypassing link-scanning and banner-based user-training defences. The use of PetitPotam coercion in Campaign B, even when blocked, signals that at least one actor behind this pattern was pursuing domain-level compromise as the objective, not merely initial access. The concurrent operation of at least three independently tracked clusters—Spring Ring, UNC6692, and STAC4749—using the same Teams external access vector over the same six-month window confirms this is now a commoditised attack pattern being used by financially motivated groups with varying sophistication levels and ranging from custom malware deployment to ransomware. The fundamental defensive gap is structural: Teams external federation is enabled by default, RMM tools are legitimate, and voice interaction bypasses every link-centric detection control, meaning organisations without behavioural identity analytics and tightly scoped external access policies remain broadly exposed.
What happened
Between January and April 2026, an unattributed threat cluster Unit 42 designated Spring Ring conducted coordinated voice phishing operations via external Microsoft Teams accounts, impersonating IT help desk personnel across at least 10 organisations. Attackers exploited Teams' default 'Chat with Anyone' feature to initiate unsolicited chats and live voice calls, coercing targets into executing remote management tools or custom malware. Two distinct campaigns are documented: Campaign A deploying an obfuscated PowerShell remote access trojan, and Campaign B escalating to a PetitPotam-based NTLM relay attempt against a domain controller. At least two independent research organisations (Mandiant and Sophos) tracked separate clusters using the same attack vector concurrently.
Affected scope
More than 150 employees across at least 10 organisations in unspecified industries (Spring Ring direct); parallel campaigns extended confirmed impact to financial services, healthcare, manufacturing, energy, and construction sectors, primarily in Canada and the United States.
Technical assessment
Attackers registered external Microsoft 365 tenants using display names and domain suffixes that project internal IT authority, then leveraged Teams' cross-tenant federation to contact targets directly. Voice interaction replaced malicious links, bypassing URL-scanning controls entirely. Campaign A used Quick Assist for initial remote access before deploying a nine-line PowerShell stager that set the amsiInitFailed flag to bypass AMSI, then beaconed to san-sid[.]com for a secondary payload. Campaign B used victim-specific AWS S3 URLs to deliver a custom executable dropper, established persistence via a sideloaded Microsoft Edge extension, then used Python tooling to scan for open SMB (port 445) and invoked PetitPotam to coerce NTLM authentication from a domain controller—the relay attempt was blocked in the observed instance. No software vulnerability was exploited; the attack surface is the identity and trust model of SaaS collaboration platforms.
Recommended defensive actions
- Restrict Microsoft Teams external access: audit and disable or scope the 'Chat with Anyone' setting to prevent unsolicited external contact with employees.
- Block or alert on external Teams communications from tenants using IT-authority keywords (help, support, internal, certified, network, infrastructure) in display names or domain strings.
- Audit and restrict execution of Quick Assist, RemSupp, TeamViewer, and other remote monitoring and management tools via endpoint policy, alerting on use by users with no documented support workflow.
- Enforce Extended Protection for Authentication (EPA) on domain controllers and disable NTLM where Kerberos is operationally viable, to neutralise PetitPotam-class coercion attempts.
- Deploy identity-threat detection tuned to external-entity chat-to-call transitions and rapid multi-target contact patterns from a single external identity within a short window.
- Train employees to verify any unsolicited IT contact via a separate, out-of-band channel before granting remote access, regardless of the platform origin.
Uncertainties and evidence gaps
- Spring Ring's threat actor attribution is unconfirmed; Unit 42 does not link it to a named group, and its relationship to UNC6692 or STAC4749 is not established by any published source.
- The full scope of targeted industries and organisations is not disclosed; 'various industries' leaves true exposure breadth unknown.
- Whether the PetitPotam-based NTLM relay succeeded in any incident beyond the one blocked case has not been confirmed in published reporting.
- No government or vendor advisory specifically addressing the Teams external access attack surface has been issued; defenders must rely on vendor-specific detection guidance and manual configuration changes.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
No software vulnerability exploited; Spring Ring actively conducted voice phishing via Microsoft Teams January–April 2026, confirming operational execution against 150+ employees. Parallel clusters (UNC6692, STAC4749) were separately confirmed active over the same period using identical initial access.
Investigation began with the Unit 42 primary report on Spring Ring, which provided a detailed account of two vishing campaigns active January–April 2026. Web searches confirmed that at least two separately tracked clusters—UNC6692 (Mandiant) and STAC4749 (Sophos)—were operating the same Teams external access impersonation vector concurrently, establishing that Spring Ring reflects a broader commoditised shift rather than an isolated incident. The KnowBe4 Phishing Threat Trends Report Vol. 7 independently corroborated the 41% surge in Teams-based attacks cited in the source article. No CVEs were identified and no government advisory was found; the attack surface is entirely behavioural and platform-configuration-based.
- What are the full technical details, scope, and IOCs of the Spring Ring campaign?Fetched the Unit 42 primary report.unit42.paloaltonetworks.com ↗
Two-campaign breakdown confirmed: Campaign A (Quick Assist → AMSI-bypass PowerShell RAT, C2 san-sid[.]com); Campaign B (S3 dropper → Edge extension → PetitPotam NTLM relay attempt). 26 attacker identities, 48+ spoofed accounts, 150+ targets across 10+ organisations. No CVEs exploited.
why Establishes the authoritative primary account of the event, tools, infrastructure, and IOCs.
- Are there independent reports of Teams vishing with similar TTPs operating in the same period?Searched for Microsoft Teams vishing IT help desk social engineering 2026.
Multiple independent campaigns identified: UNC6692 (Mandiant, April 2026), STAC4749/Chaos ransomware (Sophos, February–June 2026), and CyberProof H1 2026 analysis—all use the same external Teams tenant impersonation pattern.
why Confirms Spring Ring is not isolated; the Teams external access vector is being exploited by multiple distinct clusters simultaneously, elevating the assessment from a single campaign to a class of threat.
- Does the UNC6692 reporting provide attribution or additional technical context?Fetched the Hacker News article on UNC6692.thehackernews.com ↗
UNC6692 attributed to former Black Basta affiliates; uses distinct SNOW malware ecosystem (SNOWBELT, SNOWGLAZE, SNOWBASIN); targets senior executives; achieves lateral movement via pass-the-hash. No CVEs. Not directly linked to Spring Ring.
why Adds actor context and a named malware family to the broader threat picture, though UNC6692 and Spring Ring remain unlinked by published evidence.
- What is STAC4749's connection to this threat trend and what are the downstream impacts?Fetched the Bleeping Computer article on Teams vishing leading to Chaos ransomware.bleepingcomputer.com ↗
STAC4749, linked to former Conti/Royal/BlackSuit affiliates, targeted dozens of North American organisations Feb–June 2026 via Teams impersonation. Achieved encryption in under 17 hours in one case. Canada (50%) and US (45%) primary targets.
why Provides the ransomware end-game context absent from Spring Ring's own reporting, confirming the same vector is being monetised by ransomware-affiliated groups.
- Does the KnowBe4 report independently confirm the 41% Teams phishing surge cited in the Unit 42 article?Fetched the KnowBe4 2026 Phishing Threat Trends Report Vol. 7.knowbe4.com ↗
Report confirms Teams attacks surged 41% in six months. Also notes 84.4% of successful phishing now passes DMARC verification, underlining why platform-trust exploitation is effective.
why Independent statistical corroboration from a separate security vendor, validating the scale of the Teams-based phishing trend described by Unit 42.
- Does the CyberProof H1 2026 analysis provide independent sector-specific detail?Fetched the CyberProof H1 2026 Microsoft Teams vishing analysis.cyberproof.com ↗
Confirms financial services and healthcare as targeted sectors; identifies SINDOOR malware in one incident; notes Iranian state-aligned actors among suspected threat groups. Call durations averaged approximately 20 minutes.
why Extends the sector scope beyond what Unit 42 disclosed and adds a state-aligned actor dimension, though SINDOOR is not linked to Spring Ring specifically.
- Are there any government or vendor advisories specifically addressing this Teams external access attack surface?Searched for CISA or Microsoft advisories on Teams external access vishing 2026.
No government advisory directly addressing Spring Ring or the Teams external access vishing pattern was found in search results.
why Absence of formal advisory is a material gap; defenders must rely on vendor detection guidance and manual configuration hardening rather than a directed remediation notice.
Research coverage
All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 2 registered sources supplied useful evidence (1 primary, 1 corroborating, 0 contextual and 0 PoC/exploit references). 61 completed sources contained no matched information for this story.
Complete source-by-source audit 73 sources
| Source | Run result | Value | Why it was useful — or not |
|---|---|---|---|
| Unit 42news | ok1 records | Primary evidence2 matched items | Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research. |
| BleepingComputernews | ok10 records | Corroborating1 matched items | Supplied independent analysis opened and verified during focused research. |
| AlienVault OTXdark_web | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| CERT-EU Threat Intelligencenews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| CIRCL CVEcve | ok30 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| CISA Alertsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| CISA KEVkev | ok1687 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5333 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok689 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1013 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| FIRST EPSSepss | ok8075 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| GitHub topic: pocresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| GreyNoiseexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok9 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok17 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok5 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1591 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok3 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| MISP threat actor galaxyactor | ok0 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| NVDcve | ok900 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| SentinelLabsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sigma Rulesresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sophos X-Opsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| The DFIR Reportnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| The Hacker Newsnews | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| ThreatFoxthreat_intelligence | ok100 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Unit42 IOCsresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| WeLiveSecuritynews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
Additional verified pages 3 opened outside the registered collection
Technical references1
Repository captured from the source article as technical context; not validated as PoC or exploit code.
Analysis & research5
Primary Unit 42 report; full attack lifecycle, two campaign variants, IOCs, and telemetry.
Mandiant-tracked cluster using near-identical Teams impersonation TTPs; SNOW malware suite targeting senior executives.
Sophos-tracked STAC4749 campaign; same Teams external access vector leading to ransomware deployment by former Conti affiliates.
Independent corroboration of the 41% surge in Teams-based phishing attacks over six months.
Independent H1 2026 analysis of Teams impersonation attacks across financial and healthcare sectors.