- The Mess: A coordinated campaign called Spring Ring used external Microsoft Teams accounts to impersonate internal IT help desks, targeting more than 150 employees across at least 10 companies. Victims were pushed into installing remote-access tools, running malware or, in a more advanced variant, enabling an NTLM relay attack against a domain controller.
- The Damage: One convincing Teams call can move an attacker from a chat window to remote access, credential abuse and potentially the organization’s Active Directory infrastructure.
- The Fix: Restrict risky external Teams interactions, train employees to independently verify unexpected IT support calls, and investigate unusual RMM deployments, suspicious authentication activity and NTLM relay attempts.
The attacker didn’t need to break into Microsoft Teams.
They just joined the meeting.
Then they pretended to be IT.
Researchers at Unit 42 tracked a coordinated social-engineering operation called Spring Ring, active between January and April 2026. The campaign used external Microsoft Teams accounts to impersonate corporate IT support and targeted more than 150 employees across at least 10 organizations.
The chat was only the beginning.
The real attack happened on the call.
“Hi, This Is IT”
That’s the entire weapon.
Attackers contacted employees through Microsoft Teams using external accounts.
They impersonated internal support personnel.
Then came the voice call.
The objective was to convince the victim that something needed to be fixed immediately.
In one version of the campaign, attackers attempted to persuade victims to install legitimate remote monitoring and management tools or custom malware.
The software itself doesn’t always look suspicious.
That’s exactly why this works.
A remote-support tool can be legitimate.
The person asking you to install it might not be.
The Voice Call Is the Malware Delivery System
Phishing traditionally relies on the victim noticing a suspicious email.
Vishing changes the rules.
A convincing human voice can answer questions.
Apply pressure.
Claim authority.
And react when the victim hesitates.
Spring Ring exploited exactly that advantage.
The attackers didn’t need to write a perfect phishing message.
They could simply talk.
And the victim could be manipulated into performing the dangerous action themselves.
Then the Campaign Got Worse
One observed Spring Ring variant went beyond RMM tools and custom malware.
Researchers saw attackers transition from the voice-phishing stage toward an NTLM relay attack targeting an organization’s domain controller.
That’s a completely different level of danger.
The initial access is social engineering.
The next stage targets enterprise authentication infrastructure.
A fake IT support call can therefore become the first move in an attack against Active Directory.
Microsoft Teams Is Now Part of the Attack Surface
This is the uncomfortable reality.
Organizations often focus heavily on:
- suspicious email
- malicious attachments
- fake login pages
- dangerous links
Meanwhile, collaboration platforms are increasingly trusted by employees.
A Teams call feels internal.
A support message inside the corporate communication tool feels more legitimate than a random email.
Attackers know that.
Spring Ring exploited the trust associated with the communication channel itself.
External Accounts Are Enough
The attackers didn’t need to compromise every victim’s Microsoft account first.
They used external Teams accounts to establish contact.
That matters because organizations often allow external collaboration for legitimate business reasons.
Vendors.
Partners.
Contractors.
Customers.
Blocking every external account isn’t always realistic.
But treating every external caller claiming to be internal IT as trustworthy is even worse.
The Old Help Desk Scam Has New Infrastructure
There is nothing particularly futuristic about impersonating technical support.
The trick is ancient.
The infrastructure changed.
Yesterday:
phone call → install remote-access software
Today:
Microsoft Teams → corporate identity → voice call → RMM → malware → authentication attack
The human vulnerability stayed exactly the same.
The attacker simply moved into the tools companies already use every day.
What Defenders Should Watch
Organizations should investigate:
- unexpected RMM software installations
- new remote-access tools appearing after Teams conversations
- external accounts impersonating IT personnel
- unusual NTLM authentication activity
- relay attempts involving privileged systems
- suspicious domain-controller authentication requests
- employees receiving unexpected support calls
The most important control is also painfully simple.
Employees should have a reliable way to verify IT support independently.
Don’t trust the person who contacted you.
Verify through a known internal channel.
Bugstoday Opinion
Security awareness training spent years teaching people:
Don’t click suspicious links.
Attackers adapted.
Now they can call you inside the company’s own collaboration platform and explain exactly why you should ignore your security instincts.
That’s the strength of vishing.
The attacker isn’t fighting the victim’s skepticism.
They’re talking directly to it.
Spring Ring shows that collaboration platforms are no longer just productivity tools.
They’re identity infrastructure.
And once an employee believes the person on the other end is IT, the attacker doesn’t necessarily need an exploit.
The employee becomes the initial-access broker.
Bugstoday verdict: if “IT support” contacts you unexpectedly through Teams and asks you to install software or change authentication settings, don’t follow the caller’s verification process. Hang up and verify them through yours.
Today’s Bugs. Tomorrow’s Breaches.




