Teams Voice Phishing Reaches Domain Controllers

Unit 42 says Spring Ring ran from January to April 2026 and hit more than 150 employees across at least 10 companies by using external Microsoft Teams accounts to pose as IT help desk staff. What looked like ordinary chat was really a voice phishing call designed to talk victims into running remote monitoring and management (RMM) tools or custom malware. The twist is that the victim does the work for the attacker. By getting someone to launch trusted admin software themselves, the campaign slips into normal support workflows; in one variant, the path moved from the call to an attempted Microsoft NT LAN Manager (NTLM) relay attack against a domain controller, which can turn a help-desk impersonation into domain-level exposure. If your organization lets outside accounts reach employees in Teams, the blast radius is bigger than the chat thread: identity and desktop-support trust become part of the attack surface. The reporting shows that collaboration tools can be used to open the door to remote-admin access, and in the relay variant, to Active Directory infrastructure as well.

Part of the PlainSec briefing for 2026-09-01

Editions

Sources