Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [incident, spring-ring, unit-42, vishing, microsoft-teams, ntlm-relay, social-engineering] ยท confidence: high ยท severity: medium ยท affected_sectors: [Global] ยท au_impact: false

Unit 42 Details 'Spring Ring' Teams Vishing Campaign With NTLM-Relay Escalation

Summary

Palo Alto Networks Unit 42 detailed Spring Ring, a social-engineering operation between January and April 2026 that used external Microsoft Teams accounts to impersonate IT help-desk staff.

Details

The operation targeted more than 150 employees across at least 10 companies. Attackers used Teams' default "Chat with Anyone" feature to initiate direct chats with users outside their organisation, coercing victims into running remote-monitoring-and-management tools or custom malware. In a more advanced variant, the campaign pivoted from a vishing call to an NTLM-relay attack against the target's domain controller.

Unit 42 telemetry shows collaboration-tool phishing represented 42% of all Cortex phishing alerts in the first four months of 2026 (up from 30%), and KnowBe4 data shows Teams-based attacks rose 41% between October 2025 and March 2026.

Assessment

Spring Ring demonstrates the weaponisation of collaboration platforms as identity becomes the primary attack vector. The NTLM-relay escalation to a domain controller is a significant technical leap from credential-harvesting chat social engineering, and the rising share of collaboration-tool phishing signals a durable shift away from email as the default delivery channel.