Skip to content
Auto-CTI
Back to today
NEW HIGH B3

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

B Unit 42 ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Organized social engineering campaign uses external Microsoft Teams accounts to impersonate IT help desk personnel for credential theft; 150+ employees across 10+ companies targeted between January and April 2026.

Description

A coordinated social engineering operation uses external Microsoft Teams accounts to impersonate IT help desk personnel and persuade employees to disclose login credentials. The campaign, named Spring Ring, is active between January and April 2026 and targets organizations across various sectors. Attackers leverage deceptively authentic Teams messages and voice calls to build trust. After successful compromise, they download malware that moves itself to the Temp directory and establishes persistence mechanisms. The campaign demonstrates how familiar communication platforms can be abused as vectors for large-scale compromise.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
0.50
exploitability factor
1.00
days old
8.00
vendor mismatch penalty
0.00

Path: operational

ESC