Skip to content
Auto-CTI
Back to today
NEW Spring Ring HIGH C3

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

C darkreading ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The 'Spring Ring' operation uses vishing techniques specifically targeting Microsoft Teams users to enable remote access and malware distribution,not just email phishing, but direct VoIP-based social engineering against collaboration platforms.

Description

The active 'Spring Ring' campaign targets Microsoft Teams users through vishing calls to compromise credentials and gain remote access to user sessions. Attackers use voice-over-IP-based social engineering to build trust and trick users into disclosing authentication information. After successful compromise, attackers can distribute malware, take over infrastructure, and move laterally within the corporate environment. The campaign targets users of Microsoft 365 and collaboration tools and poses a significant risk to organizations relying on Teams for internal communication.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
0.60
exploitability factor
1.00
days old
6.00
vendor mismatch penalty
0.00

Path: operational

ESC