Attackers are Using Microsoft Teams Calls to Gain Access to Corporate Networks

The campaign relies on fake IT support conversations rather than phishing emails, giving attackers a different route into enterprise environments.

Teams hero approved 2

Key Takeaways:

  • Spring Ring used Microsoft Teams chats and calls to impersonate IT support personnel.
  • Researchers observed attacks targeting more than 150 employees across at least 10 organizations.
  • The campaign included attempts to deploy remote access tools and conduct NTLM relay attacks.

A new voice phishing campaign called Spring Ring is exploiting Microsoft Teams to trick employees into granting attackers access to corporate systems. Researchers observed the campaign targeting more than 150 employees across at least 10 organizations between January and April 2026.

Unlike traditional phishing attacks that rely on emails and malicious links, the Spring Ring campaign uses external Microsoft Teams accounts disguised as IT support personnel. Attackers initiate chats and voice calls, and convince victims to install remote access software or execute malicious commands that can provide unauthorized access to their devices.

Researchers documented two attack chains targeting Microsoft Teams. One focused on persuading users to run remote monitoring tools or malware, while a more sophisticated variant attempted to leverage victim interactions to launch an NTLM relay attack against a domain controller, which potentially opens the door to broader network compromise.

“The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow. This shift moves the attack from a passive click-and-harvest model to a real-time engagement. Attackers can then pivot based on the victim’s responses. Once the trust gap is crossed, the path to domain-level privileges via open-source tools like PetitPotam is short,” the Palo Alto Networks staff researcher explained.

Why Microsoft Teams is becoming a cyberattack target?

This campaign shows a major shift in cybercriminal tactics toward collaboration platforms such as Microsoft Teams. The attackers capitalize on employee trust in familiar workplace tools and use live conversations to adapt their social engineering techniques in real time.

Researchers found that the threat actors created numerous Microsoft 365 tenants and Teams identities designed to act like legitimate support staff. They combined convincing personas with repeated calls and messages and were often able to build trust and increase the likelihood that targets would follow their instructions.

What organizations should do next?

Organizations should treat collaboration platforms such as Microsoft Teams as potential entry points for cyberattacks and ensure employees are trained to be skeptical of unsolicited support requests. Staff should be trained to independently verify anyone claiming to be from the IT department, especially if they are asking users to install remote access tools, run commands, approve authentication requests, or provide sensitive information. Security awareness programs should also include voice phishing scenarios, as the Spring Ring campaign demonstrated that attackers can use live conversations to build trust and bypass traditional phishing defenses.

Administrators should review Microsoft Teams settings for external communications, monitor for suspicious activity originating from external tenants, and strengthen identity protections such as multifactor authentication and privileged access controls. Security teams should also monitor unusual use of remote management software, PowerShell activity, and authentication events that could indicate an attempted NTLM relay attack.