Spring Ring is a voice phishing operation that abused Microsoft Teams external accounts to impersonate IT help desk personnel across 150+ employees in 10+ organizations. Attackers used spoofed .onmicrosoft.com tenants to initiate chats, then transitioned to voice calls to coerce victims into executing RMM tools or custom malware. Two campaign variants were observed: Campaign A delivered an obfuscated PowerShell RAT from san-sid.com with AMSI bypass, while Campaign B used tailored S3-hosted executables and attempted PetitPotam NTLM relay attacks against domain controllers for domain-level privilege escalation.
NTLM Relay
2 posts
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams Thus Spoke…The Gentlemen A recent leak of internal communications and backend data from 'The Gentlemen' RaaS operation has revealed the group's highly structured operational model and mature toolset. The threat actors actively exploit edge appliances and NTLM relay vulnerabilities for initial access, followed by extensive use of red-team tools and custom EDR evasion techniques to deploy their cross-platform ransomware.