Security1 distinct publisher2 min readPublished
Unit 42 says the crew reached more than 150 employees at ten or more companies without a single software exploit, which puts Teams federation policy and NTLM relay hardening in scope and leaves the endpoint downstream.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Teams already labels the stranger. Unit 42's own figure shows the warning Microsoft raises when an external identity opens a chat with a user [12]. Chats still landed in front of more than 150 employees at 10 or more organizations, an average of at least 15 targets per company [16], which reads as spraying inside each tenant rather than selecting individuals.
The second variant is the part that moves the control surface. Unit 42 says no software exploit is involved: the operators rely on live voice and on the trust employees place in SaaS collaboration platforms [9]. It also says that once the trust gap is crossed, the walk to domain-level privileges using open-source tools such as PetitPotam is short [11]. Put those together and the chain runs on configuration at both ends, namely who may open a chat into the tenant, and whether authentication relayed at a domain controller is accepted. Neither question resolves on the endpoint.
The trend figures deserve a closer read than the percentages suggest. Collaboration-tool phishing went from 30 percent to 42 percent of phishing alerts in Cortex across consecutive four-month periods [6], which is 12 points absolute and a 40 percent relative rise [14]. That is Palo Alto's own telemetry from its own install base, published in a post that also lists Cortex and Idira products as the mitigation [13]. KnowBe4's 41 percent covers October 2025 to March 2026, overlapping Unit 42's January to April window by three months [15], so the two numbers are one directional reading of a shared quarter rather than independent corroboration.
The outcome itself goes unreported. Unit 42 describes attempted payload delivery across two campaigns using two distinct vectors [5], gives no count of employees who executed anything, and names no threat group behind Spring Ring [19]. APT29, cited as prior art, ran Teams abuse the older way, with malicious links and fake Entra ID tenants aimed at harvesting credentials [8]. The delta is real-time audio, which lets the operator pivot on a hesitant victim, and which leaves thinner records than the file operations and mailboxes responders normally review [10]. Unit 42's framing is that identity has become the primary attack vector here [17]; the operational version of that is that the intrusion has a tenant and a federation setting behind it before it has a process tree.
Ranked by verification strength, evidence, and original report placement.
Unit 42 uncovered a coordinated social engineering operation between January and April 2026 that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel; it names the activity Spring Ring.
Unit 42 telemetry shows the operation targeted more than 150 employees across at least 10 companies in various industries.
The Teams chat is a setup for a voice phishing call during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware.
In a more advanced variant, attackers transitioned from the vishing call to a full NTLM relay attack aimed at the organization's domain controller.
Unit 42 breaks down two observed campaigns, both involving vishing manipulation that resulted in attempted payload delivery via two distinct attack vectors.
In the first four months of 2026, phishing alerts from collaboration tools represented 42% of all phishing alerts in Cortex, up from 30% in the preceding four months.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
science
Unit 42 counted 405 AI malware samples. Twelve reached a real endpoint.1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific, and all from one desk
The particulars are the kind you can act on before lunch: adversary-controlled .onmicrosoft.com tenants spelled out, help desk display names, PetitPotam named as the route to domain privileges. But every figure — 150-plus targets, ten-plus companies, 26 identities, the 42% alert share — is Palo Alto Networks measuring its own telemetry, and the one external number, KnowBe4's 41%, is a link rather than a document we can inspect.
Attempted, never confirmed landed
Ten organizations and 150 people is a real footprint, and since the hunt only started when a new Teams detection suite lit up, the count reads as a floor. What is measured, though, is attacker reach: Unit 42 stops at attempted payload delivery and never says a single victim ran the RMM tool or that the relay reached a domain controller.
Domain controllers in the framing, attempts in the findings
The memorable ending — relaying NTLM at a domain controller — belongs to one 'more advanced variant', while the base case is a stranger with a help desk display name talking someone into installing a remote management agent. Stack the eight-product protection list on top and the framing sits ahead of what was actually observed. Not far ahead: the infrastructure and the choreography are concrete, and Unit 42 pointedly refuses to blame a Microsoft flaw.
The measurer sells the meter
One company named the threat, generated the telemetry, built the detection suite that found it, published the trend line, listed eight of its own products as the remedy and closed with a link to its incident response team. None of that makes Spring Ring invented. It does mean the two facts a buyer would act on — that collaboration tools now dominate phishing signal, that voice is the unmonitored gap — are both certified by the party selling monitoring for both.
Credible mechanics, unaudited numbers
Two things prop this up: the tradecraft is dull enough to be true — throwaway Microsoft 365 tenants, a calm professional voice, a well-known coercion tool — and the author draws boundaries it did not have to draw, declining to name an actor or a Microsoft vulnerability. Two things hold it down: a single publisher with a commercial stake, and an outcome column that reads 'attempted' the whole way down.