Spring Ring Vishing Campaign Exploits Microsoft Teams for Malware Deployment
A coordinated vishing campaign, dubbed Spring Ring, targeted employees across various industries in early 2026. The attackers used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers.
The campaign ran between January and April 2026 and reached over 150 employees at more than 10 companies. Attackers registered external Microsoft Teams tenants with names built to resemble internal IT departments, such as 'ITProtectionDepartment' or 'MandatoryNetworkMonitoring', using the onmicrosoft.com format.
The attackers used specific names rather than generic titles like 'help desk' to increase the perceived authenticity of the technician. Researchers found 26 distinct attacker identities behind the chat and call attempts.