Phishing

New ‘Spring Ring’ operation uses vishing via Microsoft Teams

Microsoft Teams website on a tablet. Teams is a unified team communication and collaboration platform with workplace chat, video meetings, and file storage.

As reported by Dark Reading, a coordinated operation dubbed "Spring Ring" has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks. The campaign aims to install remote monitoring and management (RMM) and malware tools, and in some instances, compromise organizations' domain controllers, according to Palo Alto Networks.

The "Spring Ring" operation, observed between January and April, illustrates a shift from traditional email phishing to attacks leveraging trusted enterprise collaboration platforms like Microsoft Teams. Attackers initiate contact through seemingly legitimate chats, impersonating internal IT support. They then conduct vishing calls, attempting to trick users into executing RMM tools or custom malware. A more advanced tactic involves attempting NTLM relay attacks against domain controllers.

Researchers from Palo Alto Networks noted that the campaign targeted employees across at least 10 organizations. The operation highlights the growing trend of social engineering attacks that exploit the perceived authenticity of interactions within collaboration tools. Defenders are advised to enhance user education beyond traditional phishing awareness to include specific scenarios mimicking these vishing attacks and to implement robust behavioral monitoring to detect identity-based anomalies.

Source: Dark Reading

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds