{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/teams/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft Teams","Quick Assist"],"_cs_severities":["high"],"_cs_tags":["phishing","social-engineering","identity","teams","vishing"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Spring Ring campaign, active between January and April 2026, represents an evolution in social engineering by integrating voice phishing (vishing) directly into the Microsoft Teams workflow. By exploiting the \u0026quot;Chat with Anyone\u0026quot; feature, attackers establish external connections with enterprise users while impersonating internal IT help desk personnel. These actors utilize professional, urgency-focused display names and provision Microsoft 365 tenants with .onmicrosoft.com subdomains to mirror legitimate corporate infrastructure.\u003c/p\u003e\n\u003cp\u003eOnce contact is established through Teams chat, the attackers initiate audio calls to manipulate victims into executing unauthorized RMM tools or custom PowerShell-based remote access Trojans (RATs). Beyond initial access, the campaign demonstrates advanced post-exploitation capabilities, including the use of tools like PetitPotam to perform NTLM relay attacks against target domain controllers. With 150 employees targeted across at least 10 companies, this campaign highlights the shift toward using trusted collaboration platforms as a primary vector for identity-based attacks.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttackers establish an external Microsoft 365 tenant using a deceptive name (e.g., ITProtectionDepartment.onmicrosoft.com).\u003c/li\u003e\n\u003cli\u003eAttackers initiate a Microsoft Teams chat with a target, masquerading as an internal IT help desk member.\u003c/li\u003e\n\u003cli\u003eAttackers place a voice call to the target via the Microsoft Teams platform to build trust and pressure the victim.\u003c/li\u003e\n\u003cli\u003eThe attacker manipulates the victim into executing a payload, such as a malicious PowerShell script or an RMM utility (e.g., Quick Assist).\u003c/li\u003e\n\u003cli\u003eThe execution of the malicious script bypasses AMSI and provides the attacker with remote access to the victim workstation.\u003c/li\u003e\n\u003cli\u003eAttackers use the compromised host to perform internal network reconnaissance.\u003c/li\u003e\n\u003cli\u003eAttackers utilize NTLM relay tools (e.g., PetitPotam) to force authentication from a Domain Controller toward attacker-controlled infrastructure.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved, resulting in unauthorized access or privilege escalation within the target domain.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe Spring Ring campaign targeted at least 10 major organizations, impacting over 150 employees. Successful exploitation allows for complete workstation compromise, remote control, and the potential for domain-level privilege escalation via NTLM relay attacks against Domain Controllers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Microsoft Teams \u0026quot;External Access\u0026quot; policies to block communication from untrusted domains or specific .onmicrosoft.com tenants not explicitly allowlisted.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous process creation events associated with common RMM utilities (e.g., Quick Assist, TeamViewer) when launched by non-IT personnel.\u003c/li\u003e\n\u003cli\u003eImplement and enforce strict SMB signing and LDAP signing to mitigate NTLM relay attacks such as those utilizing PetitPotam.\u003c/li\u003e\n\u003cli\u003eDeploy detections for suspicious PowerShell patterns, specifically those attempting to disable AMSI or initiate unauthorized network connections.\u003c/li\u003e\n\u003cli\u003eEducate end-users on identifying and reporting \u0026quot;Chat with Anyone\u0026quot; requests from external users claiming to be internal IT support.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T11:54:52Z","date_published":"2026-08-31T11:54:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-spring-ring/","summary":"The Spring Ring campaign is a coordinated voice phishing operation impersonating IT help desk staff via Microsoft Teams to coerce victims into executing remote access tools or facilitating NTLM relay attacks against domain controllers.","title":"Spring Ring Voice Phishing Campaign Targeting Microsoft Teams","url":"https://feed.craftedsignal.io/briefs/2026-08-spring-ring/"}],"language":"en","title":"CraftedSignal Threat Feed - Teams","version":"https://jsonfeed.org/version/1.1"}