{
  "id": 4750748,
  "title": "Spring Ring: From Microsoft Teams Voice Phishing to RMM, RAT, and NTLM Relay",
  "url": "https://urgent.news/2026/09/01/spring-ring-from-microsoft-teams-voice-phishing-to-rmm-rat-and-ntlm",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T00:37:04.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/spring-ring-from-microsoft-teams-voice-phishing-to-rmm-rat-and-ntlm-relay-3k29"
  },
  "original_language": "en",
  "account": "Spring Ring is a sophisticated voice phishing campaign targeting Microsoft Teams users. The attackers create external Microsoft Teams accounts to impersonate corporate IT staff, using voice calls to deceive targets into running remote monitoring and management (RMM) tools or custom malware. In some cases, the attackers attempt to perform NTLM Relay against domain controllers using PetitPotam.\n\nThe attack begins with an external Teams chat or voice call from an external tenant, impersonating IT staff. The attacker quickly establishes trust by prompting the target to run an RMM tool or execute an executable file. For Campaign A, the target is tricked into running a legitimate RMM tool like Quick Assist to enumerate devices and the domain. For Campaign B, the attacker delivers a malicious executable via a specially crafted S3 URL, establishing persistence and a hidden Edge instance. The attacker then scans internal TCP/445 and triggers NTLM authentication toward the domain controller, attempting to force authentication using PetitPotam and gain domain privileges.\n\nAttackers operate from external Microsoft 365 tenants, connecting to Teams and ultimately reaching the internal network and Active Directory from the user device. Administrators should be aware of unusual RMM usage, PowerShell activity, customized S3 URLs, hidden Edge instances, and SMB/EFSRPC traffic. Success depends on the attacker's ability to establish Teams chats and calls with the target, who believes the attacker is IT staff and proceeds with the requested actions.\n\nTo mitigate risk, organizations should limit external Teams communication to necessary business needs, verify external callers through separate channels, and approve third-party RMM tools. Enabling PowerShell controls, AMSI, application control, and EDR is essential. Strengthening NTLM Relay defenses, such as SMB signing, NTLM restrictions, and Extended Protection for Authentication, can also help prevent successful attacks.",
  "summary": "1. Overview Article Title : Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams Source : Unit 42 Published Date : 2026-08-31 Original Source : Unit 42 Related Sources : None Related Malware, Threat Groups, CVEs, Products : Spring Ring, PowerShell RAT, Microsoft Teams, Microsoft Quick Assist, Microsoft Edge, Active Directory Severity : High 2. Executive Summary Spring Ring…",
  "key_points": [],
  "editors_take": "This campaign's use of Microsoft Teams to impersonate IT staff and trick users into running malware or divulging credentials highlights the need for stricter external communication controls and verification protocols.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}