Executive Summary
Between January and April 2026, the "Spring Ring" threat operation targeted over 150 Microsoft Teams users across 10+ organizations using sophisticated voice phishing (vishing) attacks. Attackers impersonated internal IT support staff through Teams chats, then conducted voice calls to trick employees into installing remote access tools or executing malware. The most advanced variant employed NTLM relay attacks targeting domain controllers for full infrastructure compromise, demonstrating a significant evolution from traditional email phishing to real-time social engineering through trusted collaboration platforms.
This incident reflects the accelerating shift toward platform-native attacks as threat actors exploit the inherent trust users place in enterprise collaboration tools. With vishing attacks doubling in the first half of 2026 according to CrowdStrike data, organizations face an urgent need to reassess security controls around identity verification and SaaS platform governance as traditional perimeter defenses prove inadequate against socially-engineered compromise vectors.
Why This Matters Now
Spring Ring represents a critical inflection point where trusted collaboration platforms become primary attack vectors, forcing organizations to rethink identity verification and user education as vishing attacks surge 100% year-over-year in 2026.
Attack Path Analysis
Spring Ring attackers initiated Microsoft Teams vishing calls impersonating IT support to trick users into installing RMM tools or malicious executables. After gaining remote access, they performed reconnaissance and attempted privilege escalation through NTLM relay attacks targeting domain controllers. The attackers moved laterally within networks while maintaining persistent command channels through hidden browser instances and custom extensions. They established covert communication channels and attempted to exfiltrate sensitive organizational data. The campaign aimed to achieve domain-level compromise for widespread organizational impact through infrastructure takeover.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers created fake Microsoft Teams identities mimicking IT support staff and initiated vishing calls to trick users into installing legitimate RMM tools or executing malicious payloads hosted on cloud infrastructure
MITRE ATT&CK® Techniques
Phishing: Spear Phishing Voice
Remote Access Software
Phishing: Spear Phishing via Service
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Command and Scripting Interpreter: PowerShell
Brute Force
System Information Discovery
Remote System Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication Implementation
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
CISA ZTMM 2.0 – Identity Verification
Control ID: ID.AM-2
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Identity Management
Control ID: A.8.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Microsoft Teams vishing attacks directly target IT infrastructure, exploiting collaboration platforms to compromise domain controllers and deploy remote access tools across enterprise networks.
Financial Services
Social engineering through trusted collaboration platforms poses severe risks to financial institutions, potentially enabling NTLM relay attacks against critical domain infrastructure and compliance violations.
Health Care / Life Sciences
Vishing attacks targeting Microsoft Teams users threaten HIPAA compliance through unauthorized remote access, malware deployment, and potential compromise of healthcare communication and patient data systems.
Professional Training
Training organizations face heightened risk as Spring Ring attacks exploit help desk workflows, requiring updated security awareness programs beyond traditional email phishing methodologies.
Sources
- Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Usershttps://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-usersVerified
- Spring Ring Campaign: Vishing Attacks Through Microsoft Teamshttps://unit42.paloaltonetworks.com/spring-ring-vishing-teams/Verified
- CrowdStrike Threat Hunting Report 2026 - Vishing Trendshttps://www.crowdstrike.com/resources/reports/threat-hunting-report/Verified
- CISA Advisory on Social Engineering Through Collaboration Platformshttps://www.cisa.gov/news-events/alerts/collaboration-platform-threatsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain the Spring Ring campaign's lateral movement and domain-level compromise attempts through network segmentation and east-west traffic controls. The attackers' ability to conduct NTLM relay attacks and move between systems would likely be limited by identity-aware routing and workload isolation policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Remote access tool deployment may be constrained through segmented network access controls that limit the scope of initial compromise to isolated network segments.
Control: Zero Trust Segmentation
Mitigation: NTLM relay attacks targeting domain controllers would likely be constrained by zero trust segmentation policies that restrict unauthorized communication paths to critical infrastructure components.
Control: East-West Traffic Security
Mitigation: Lateral movement capabilities would likely be reduced through east-west traffic inspection and policy enforcement that constrains unauthorized inter-system communication and credential-based traversal across network segments.
Control: Multicloud Visibility & Control
Mitigation: Covert command channels may be constrained through multicloud visibility controls that limit unauthorized outbound communication patterns and reduce the effectiveness of persistent backdoor mechanisms.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained by egress security policies that limit unauthorized outbound data transfers and reduce access to external cloud storage destinations.
Domain-wide impact potential would likely be significantly reduced with compromise scope limited to isolated network segments rather than achieving enterprise-wide infrastructure takeover and widespread disruption.
Impact at a Glance
Affected Business Functions
- IT Help Desk Operations
- Internal Communications
- Remote Access Management
- Domain Administration
Estimated downtime: 3 days
Estimated loss: $75,000
Potential exposure of domain controller authentication credentials, internal network topology information, and organizational communication logs. Attackers gained temporary remote access to victim workstations and attempted to escalate privileges to domain-level compromise across at least 10 organizations affecting 150+ users.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement and limit blast radius of compromised accounts
- • Deploy Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns across collaboration platforms
- • Enforce Egress Security & Policy Enforcement to block unauthorized outbound communications and data exfiltration attempts to attacker-controlled infrastructure
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal user behavior and detect vishing-related remote access tool deployments
- • Establish Cloud Native Security Fabric (CNSF) controls to provide real-time inspection and autonomous response to social engineering attacks targeting SaaS platforms



