A coordinated vishing campaign named Spring Ring abused external Microsoft Teams tenants to impersonate internal IT support, tricking employees into installing malware or granting remote computer access. The campaign, active from January to April 2026, targeted over 150 employees across multiple industries. No specific software vulnerability, CVSS score, or patch is detailed; mitigation focuses on user awareness and securing external collaboration settings.
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. The campaign ran between January and April 2026 and reached more than 150 employees at more than 10 companies in different industries. The attackers registered external Microsoft Teams tenants with names built to resemble internal IT … More → The post Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks appeared first on Help Net Security .