Criminal Group 'Spring Ring' Launches Vishing Campaign Against Microsoft Teams Users
A newly identified cyber‑crime operation called "Spring Ring" is targeting users of Microsoft Teams with phone‑based phishing, or vishing, in an effort to hijack active sessions and install malicious software.
The attackers typically call victims, posing as technical support staff, and request login details or consent to remote assistance. By exploiting the collaboration platform's built‑in remote‑control features, they can gain direct access to a user's session without needing to breach the network first.
According to the Dark Reading report that first described the scheme, the group’s ultimate goals include spreading malware across compromised accounts and, in more advanced cases, taking control of broader corporate infrastructure that relies on Teams for communication and file sharing.
Microsoft Teams has become a staple for many businesses since the pandemic drove a shift to remote work, making it a lucrative target for threat actors. Similar phishing and credential‑stealing campaigns have surfaced in recent years, but the focus on live session hijacking via vishing marks a notable escalation in technique.
Security analysts say the scammers often use spoofed caller IDs to appear legitimate and may reference recent corporate events or internal projects to increase credibility. Victims who unwittingly grant access can find malicious links or files delivered through the Teams chat, which can then execute ransomware, spyware, or other payloads.
Microsoft has urged organizations to reinforce multi‑factor authentication, educate employees about verifying unsolicited support calls, and to monitor for unusual remote‑control activity within the platform. IT departments are also advised to implement strict policies around who can request remote access and to use call‑back verification procedures.
Law enforcement agencies are reportedly tracking the group, but experts warn that the low cost and high success rate of vishing attacks will likely keep them active. Companies are encouraged to conduct regular phishing simulations and to keep software patches up to date to reduce the attack surface.
Comments (0)
Be the first to comment.
Join the discussion