Cookie Consent by Free Privacy Policy Generator

Microsoft Teams weaponised in Spring Ring voice phishing campaign

Palo Alto Networks Unit 42 has published research into a campaign dubbed Spring Ring, which abuses Microsoft Teams and voice phishing techniques to deploy malware and target enterprise domain controllers. The campaign uses social engineering to establish contact with victims via Microsoft Teams, then progresses to voice calls where attackers impersonate IT support or trusted contacts to convince users to install malicious software. Once access is gained, attackers move laterally within the network with a focus on compromising domain controllers, which provide centralised authentication and control over user accounts and permissions. The research highlights how collaboration platforms like Teams, which are trusted and widely used across UK businesses, are being weaponised for initial access and social engineering at scale.

Why this matters for UK organisations

For UK organisations using Microsoft Teams, this campaign illustrates how attackers are adapting traditional phishing and vishing techniques to collaboration tools that employees use daily and are conditioned to trust. Teams allows external communication by default in many configurations, and users may not immediately recognise when a contact is outside their organisation or when a call is part of a coordinated attack. The focus on domain controllers reflects a clear intent to gain persistent, privileged access that can be used for ransomware deployment, data theft or long-term espionage. Collaboration platforms are now a primary vector for social engineering because they combine trusted branding, real-time communication, and the ability to share files and links in a context where users are less suspicious than they might be with email. Organisations should consider whether external access policies in Teams are appropriately configured, whether users are trained to recognise social engineering via collaboration platforms, and whether monitoring is in place to detect unusual authentication activity or attempts to access domain controllers from unexpected locations or devices.

What to review

UK organisations should review external access settings in Microsoft Teams, including whether external communication is enabled by default, whether users can be contacted by anyone outside the organisation, and whether external contacts are clearly labelled in the interface. User awareness training should include specific guidance on how to verify the identity of external contacts, how to recognise social engineering via collaboration platforms, and what to do if contacted unexpectedly by someone claiming to be from IT support or a trusted partner. Technical controls should include monitoring for unusual authentication activity, attempts to access domain controllers from unexpected locations or devices, and the installation of software following external communication. Privileged access to domain controllers should be protected with strong authentication, conditional access policies, and regular review of who has administrative rights. Collaboration tools are now a primary vector for social engineering, and security controls need to reflect that reality.

Source: Palo Alto Networks Unit 42

News and blog posts
Today's brief highlights how familiar attack techniques continue to evolve...
McKesson, one of the largest pharmaceutical and medical device distributors in...
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two...
Palo Alto Networks Unit 42 has published research into a campaign dubbed Spring...