CuraSec

Act active

Spring Ring campaign uses Teams voice phishing to hit domain controllers

2026-08-31 18:00 UTC · Unit 42 · read the source ↗ #vishing#microsoft-teams#malware
  • Engineer — Learn: No CVE or patch required; the attack path abuses Teams social engineering rather than a software flaw, so review Teams external-access settings and restrict who can initiate calls from outside the tenant.
  • SOC/IR — Act: Active enterprise campaign targeting domain controllers via Teams vishing — hunt for anomalous Teams call activity from external tenants followed by process execution or lateral movement, and review Unit 42’s published TTPs for detection rule development.
  • Leader — Plan: Campaign targets enterprise domain controllers through a trusted communication channel (Teams), raising both breach-risk and vendor-trust questions — brief IT leadership and consider tightening external Teams communication policies this quarter.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.