Spring Ring is a voice phishing operation that abused Microsoft Teams external accounts to impersonate IT help desk personnel across 150+ employees in 10+ organizations. Attackers used spoofed .onmicrosoft.com tenants to initiate chats, then transitioned to voice calls to coerce victims into executing RMM tools or custom malware. Two campaign variants were observed: Campaign A delivered an obfuscated PowerShell RAT from san-sid.com with AMSI bypass, while Campaign B used tailored S3-hosted executables and attempted PetitPotam NTLM relay attacks against domain controllers for domain-level privilege escalation.
Spring Ring
1 post
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams