Unit 42 identified Spring Ring, a coordinated social-engineering operation that used external Microsoft Teams accounts posing as IT help-desk staff to target more than 150 employees at at least 10 organizations. Between January and April 2026, operators combined Teams chats with voice-phishing calls to create urgency and persuade victims to install remote-monitoring-and-management tools or execute malware—a vishing approach aligned with MITRE ATT&CK technique T1566.004.
One campaign obtained remote access, enumerated hosts and domains, and delivered an obfuscated PowerShell RAT dropper from san-sid[.]com; the dropper disabled AMSI before retrieving additional payloads. A second campaign used tailored executables for persistence, launched a headless Edge browser with a sideloaded extension, scanned SMB services, and attempted a PetitPotam-based NTLM relay attack against a domain controller for domain-level privileges. Cortex XDR blocked observed malware execution, while Unit 42 Managed Detection and Response stopped the attempted domain takeover.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Between January and April 2026, the Spring Ring operation used external Microsoft Teams accounts impersonating IT help desk and administrator staff to target more than 150 employees across at least 10 organizations. Operators escalated Teams chats into vishing calls to induce victims to grant remote access or execute malicious tools; Unit 42 found no evidence of a Microsoft Teams or Microsoft 365 compromise.
A Teams and Quick Assist social-engineering campaign delivered update-themed malicious MSIs that installed a portable Node.js runtime and encrypted JavaScript implant with per-user persistence, HTTPS polling, reconnaissance, and screenshot capture. Operators then enumerated Active Directory and used WinRM to access domain-joined systems including domain controllers and certificate authorities.
After obtaining Windows Quick Assist access, operators deployed malicious MSI installers from Amazon S3 that used signed applications such as Kodi, Salamander, and FileZilla to sideload malicious DLLs. The DLLs communicated with AWS API Gateway endpoints, used WMI to launch reverse-shell agents, and established persistence through a Startup-folder shortcut; the disclosure supplied related domains and SHA-256 hashes.
Researchers reported Spring Ring infrastructure including san-sid.com, 16 associated IP addresses, and SHA-256 hash 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b. The disclosure also identified IT-support-themed onmicrosoft.com accounts used to impersonate help-desk personnel in Teams.
In Campaign B, tailored Amazon S3-hosted executables established persistence, launched headless Edge with a sideloaded extension, and scanned internal systems over SMB. The activity attempted PetitPotam-based authentication coercion and NTLM relay against a domain controller for domain-level privileges, but Unit 42 Managed Detection and Response blocked the takeover attempt.
In Campaign A, attackers persuaded victims to use Windows Quick Assist or install remote-monitoring-and-management software, then enumerated host and domain groups. They downloaded an obfuscated PowerShell RAT dropper from san-sid[.]com that disabled AMSI, collected and encrypted host data, and beaconed for additional payloads; Cortex XDR blocked execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
18 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcecyberveille.ch
Open sourcedecipher.sc
Open sourcescworld.com
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceknowbe4.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.