Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation is a sophisticated campaign targeting Microsoft Teams users through vishing attacks, leveraging trusted collaboration platforms to gain remote access and install malware. Threat actors are increasingly using IT support workflows to impersonate legitimate internal units and successfully coerce victims into granting remote control or executing malicious payloads, including NTLM relay attacks aimed at compromising domain controllers. Defenders need to adapt their security strategies beyond traditional awareness training to address this evolving threat landscape.
The "Spring Ring" operation represents a significant shift in threat actor tactics, moving beyond traditional email phishing to exploit trusted collaboration platforms like Microsoft Teams. Researchers at Palo Alto Networks have observed a coordinated campaign targeting at least 150 Microsoft Teams users across multiple companies between January and April, with the goal of compromising users and gaining remote access to their systems. The campaign utilizes vishing – social engineering through voice calls – to impersonate legitimate IT support units and trick users into granting remote control or executing malicious payloads.
Attacks begin with the creation of a Microsoft Teams chat that mimics an organization's internal support units, with attackers using professional and urgency-focused display names such as "help desk" or "IT assistance." Once a chat is established, the attacker initiates a voice call, posing as an IT representative to gain the victim's trust. The attacker then guides the targeted employee through the steps to install remote access tools like Windows Quick Assist or third-party RMM software, ultimately gaining remote control.
However, the campaign goes further than simple remote access. A more advanced attack vector involves leveraging NTLM relay attacks, specifically utilizing PetitPotam, to attempt to compromise an organization's domain controller. This involves directing victims to organization- and user-specific files hosted in cloud infrastructure, which turn out to be executables designed to establish persistence, launch a hidden Microsoft Edge instance, and sideload an extension. The attackers then conduct internal network reconnaissance and generate NTLM authentication traffic, aiming to coerce a domain controller into authenticating to attacker-controlled infrastructure – a successful takeover could lead to domain-level compromise.
Researchers observed at least two distinct attack vectors employed by Spring Ring. Beyond the remote access and NTLM attacks, the campaign demonstrates a persistent effort to engage with victims, including multiple attempts and voicemails. The attackers are leveraging IT support processes to gain access to systems, effectively targeting the "locksmith" rather than breaking into a single account.
To combat this evolving threat, Palo Alto Networks recommends robust behavioral monitoring to identify identity-based anomalies and adapt security strategies beyond traditional awareness training. Organizations need to help users recognize and respond to suspicious behavior, such as unsolicited external communication from impersonated IT support units. Looking ahead, attackers are likely to further refine their ability to operate within SaaS ecosystems, utilizing collaboration platforms to access sensitive documentation and workflows.
