'Spring Ring' Gang Unleashes Vishing Attacks on Microsoft Teams Users
The threat group 'Spring Ring' has been conducting coordinated voice phishing (vishing) attacks on Microsoft Teams users across multiple companies, aiming to install remote monitoring and management (RMM) tools or malware onto their machines. At least 150 users from at least 10 organizations were targeted between January and April this year.
The attackers create a benign chat in Microsoft Teams that uses identities mirroring an organization's legitimate internal support units, then initiate a voice call with the victim, who believes they're talking to their own IT department. The attacker guides the victim through steps to grant remote control or execute malicious payloads, depending on which attack vector is employed.
The researchers observed two separate attacks by Spring Ring once engagement with a victim is established. The first uses legitimate RMM tools as an entry point, persuading victims to give the attacker remote control, while the second aims to take over the organization's infrastructure through an NTLM relay attack on the domain controller.
Palo Alto Networks' Noam Sala notes that Spring Ring represents a growing shift away from traditional email phishing toward attacks conducted through trusted enterprise collaboration platforms. The attackers are leveraging IT support processes to carry out attacks, targeting the 'locksmith' rather than breaking into individual accounts or systems.