The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

September 2, 2026

A coordinated operation has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks aimed at installing remote monitoring and management (RMM) and malware tools onto their machines. The campaign also attempts in some instances to compromise organizations' domain controllers.

Researchers from Palo Alto Networks observed the operations — which they've dubbed "Spring Ring" — between January and April attacking employees across at least 10 organizations, according to a report published this week. The campaign illustrates a growing shift away from traditional email phishing toward attacks conducted through trusted enterprise collaboration platforms, which adds authenticity to the interaction.

"The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow," Noam Sala, a Palo Alto Networks staff researcher, wrote in the post. "This shift moves the attack from a passive click-and-harvest model to a real-time engagement."