Microsoft Teams Users Targeted in Coordinated Social Engineering Campaign
A recent operation in Microsoft Teams has been uncovered by Unit 42, revealing a coordinated social engineering campaign that targeted over 150 employees across at least 10 companies. The operation, dubbed 'Spring Ring,' leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel and exploit the trust gap between employees and collaboration platforms.
The attackers used vishing calls to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, they transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC).
The operation represents an evolution in collaboration attacks, merging vishing into the Teams workflow and moving the attack from a passive click-and-harvest model to real-time engagement.