Build1 distinct publisher3 min readPublished
Unit 42 traced two campaigns that open with a Teams chat and an immediate voice call from an external tenant, which puts the question of who can ring your staff in the same bucket as who can sign in as them.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
The precondition list is where the engineering decision actually sits. Unit 42 gives four: the attacker can start Teams chats and calls from an external tenant, the target believes the caller is IT and launches the tool, the endpoint is permitted to talk to C2, SMB and domain controllers, and the relay preconditions around authentication, signing and certificate services remain in place [9]. Three of those are configuration states somebody in your organisation set, and the fourth is a person reading a display name [22].
The chain is also broken into four confirmation stages, and the first two are a chat or short call arriving from an external Teams ID, then the user answering and starting to interact [19]. Nothing has executed yet at that point, so half the documented chain sits outside the reach of endpoint tooling [23], which is why the identity indicators carry the load: chats and calls from external onmicrosoft.com tenants, and the same external ID touching several users in a short window [14].
Read the Quick Assist mitigation as a statement about the default. Approval has to be required in order to stop standard users from running it [11], so today a standard user can start the session. The endpoint indicator list puts QuickAssist.exe next to unauthorized RMM [17], meaning the process name does not tell you which one you are looking at; only the surrounding authorisation record does, and that record is the thing the mitigation asks you to create.
Campaign B's relay attempt failing is a property of the Active Directory configuration in the environments Unit 42 watched, not of the technique [8]. The report names the precondition categories but not which control held [9]. For that outcome to transfer to your estate, SMB signing, NTLM restrictions and Extended Protection for Authentication would already have to be where the remediation list wants them [13]. Absent that, the finding is best read as blocked in that environment specifically, not blocked as a rule.
One artifact is unusually cheap to alert on. The Campaign B payload arrives from an S3 URL that contains the target's name, alongside traffic to san-sid.com [18]. A per-target string in a proxy log is a high-signal detection that does not depend on decoding obfuscated PowerShell [5].
Unit 42 also logged many failed and missed calls [20], which is the most help-desk-like detail in the whole campaign.
Of the listed mitigations, restricting external Teams communication to business needs and verifying external callers on a separate channel are the only two that act before the call lands [10]. Everything else on the list catches execution after the target has already been convinced [12].
Ranked by verification strength, evidence, and original report placement.
The attacker uses Python to scan internal TCP/445 and triggers NTLM authentication toward the domain controller.
The attacker forces authentication using PetitPotam and attempts to gain domain privileges via NTLM Relay, though this was blocked in the observed cases.
Spring Ring uses external Teams accounts to impersonate corporate IT staff and uses voice calls to trick targets into running RMM tools or custom malware; in advanced cases it attempts NTLM Relay against domain controllers using PetitPotam.
The attacker sets up an external onmicrosoft.com tenant and a display name to impersonate the IT department.
The attacker sends a one-on-one Teams chat to the target, followed immediately by a voice call, to build trust and urgency.
In Campaign A the attacker tricks the target into running an RMM tool such as Microsoft Quick Assist to enumerate devices and the domain.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Spring Ring impersonated the help desk over external Teams accounts to relay NTLM at domain controllers1 distinct publisher
build
Three ways to ask who embedded your iframe, and only one the host cannot switch off1 distinct publisher
build
SynkLoader: the Teams help-desk lure now ships with a reverse proxy attached1 distinct publisher
build
height:auto is animatable now, so your max-height ceiling is a bug you can delete1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific, structured, and singly sourced
The detail is the kind investigators produce rather than infer: named processes, an EFSRPC coercion path, S3 URLs carrying target names, one command-and-control domain. But every line of it traces to a single Unit 42 write-up, restated by a dev.to author who states plainly that Unit 42 is both source and original source with no related reporting. There are no hashes, no tenant identifiers, no timeline, and no second party who has seen the same telemetry. Rich and internally coherent is not the same as verified.
Live, repeated, and unsized
This is not theory: two distinct campaigns ran, with enough call volume for Unit 42 to notice the failures and voicemails as well as the answers. What is missing is every number that would establish scale. No count of targeted users or organisations, no industries, no regions, and the reporting itself concedes that public reports do not quantify the blast radius and that domain takeover has never been confirmed. Real activity, unknown reach.
Severity label runs ahead of outcomes
A High rating and a headline path to domain controllers sit next to two campaigns that were blocked, a domain takeover nobody has confirmed, and an unquantified blast radius. That is a modest stretch, and notably the stretch is not the writing's fault — the same account volunteers each limitation instead of burying it. Our own framing, that this puts who may ring your staff in the same bucket as who may sign in as them, is the sturdier reading: the technique is durable, the demonstrated damage so far is not.
Vendor research with a product-shaped remedy
The only telemetry belongs to a security vendor's research arm, and the recommendation list ends where that vendor's market begins: application control, EDR, RMM approval workflows. Worth stating plainly — that overlap does not make the findings wrong, and the two strongest recommendations here, limiting who can start an external Teams call and verifying callers out of band, cost nothing and sell nothing. The dev.to summariser writes pseudonymously and adds no apparent commercial angle, which leaves one interested party in the chain rather than two.
Coherent account, no second witness
Confidence is capped by arithmetic, not by doubt about the reporting. One publisher, one underlying investigation, no corroboration, and no way for a reader to test the specifics beyond a single domain name. Against that, the internal consistency is good: the attack narrative, the indicator lists and the staged triage model agree with one another, and limitations are flagged rather than smoothed over. Solid enough to hunt on tomorrow, too thin to treat as settled fact.