Unit 42 has mapped a campaign it calls Spring Ring, in which attackers used external Microsoft Teams accounts to impersonate IT help desk staff and talk more than 150 employees at 10 or more companies into running malware.
Between January and April 2026, the researchers identified 26 distinct identities approaching targets with help desk style names such as “IT Assistance” and “Support Staff,” operating from external .onmicrosoft.com tenants that mimic legitimate corporate infrastructure. An innocuous-looking conversation escalates into a voice call, where the operators steer targets toward remote monitoring and management tools or bespoke malware.
A more elaborate version moved from the call into an NTLM relay attack against the organization’s domain controller, leaning on open-source tooling such as PetitPotam. Unit 42 said the activity exploits trust in SaaS collaboration platforms rather than any software flaw, and that there is no evidence of compromise in Microsoft’s products.
The campaign reflects a broader shift: collaboration tools accounted for 42% of phishing alerts in Cortex during the first four months of 2026, up from 30%, and Teams-based attacks rose 41% between October 2025 and March 2026, driven in part by the platform’s default “Chat with Anyone” feature. Voice calls also sit in a monitoring gap, less recorded and less inspected than email or file activity.
Unit 42 recommends verifying help desk identities through established channels, treating voice requests for remote access with suspicion, and watching for external-chat warning banners in Teams.
