Microsoft Teams Vishing Campaign Targets 150+ Employees With RMM and NTLM Relay Attacks
Brief
A coordinated social engineering campaign has targeted more than 150 employees across at least 10 organizations by abusing Microsoft Teams to impersonate internal IT support staff.
Tracked as Spring Ring, the campaign was active between January and April 2026 and combined voice phishing, remote monitoring and management (RMM) tools, custom malware, and NTLM relay techniques.
The attackers first created external Microsoft Teams accounts using professional-looking names such as “Help Desk,” “IT Assistance,” and “Network Support.”
Many accounts used attacker-controlled . onmicrosoft. com tenants designed to make the identities appear connected to legitimate corporate infrastructure. After initiating a chat, the attackers called victims and posed as IT technicians.
The voice interaction was central to the attack.
