Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-31 and was added to the RWP archive on 2026-09-07.
Spring Ring was Teams-as-helpdesk — 150 people, then PetitPotam toward the DC
Unit 42 31 August 2026 — Jan–Apr 2026, 150+ employees, 10+ companies. External .onmicrosoft.com “IT” tenants, 26 identities, 10–15 minute calls. Quick Assist or a personalized S3 exe. One path tried NTLM relay (PetitPotam) at a domain controller.
Bottom line up front
CONFIRMED Unit 42, 31 August 2026 — Spring Ring, January–April 2026. External Microsoft Teams tenants (ITProtectionDepartment, MandatoryNetworkMonitoring, help-desk display names on .onmicrosoft.com) chatted then called employees. >150 people at ≥10 companies. 26 attacker identities. Successful calls often 10–15 minutes. Two paths: (A) Quick Assist / RMM, then recon (whoami /groups, net group /dom), obfuscated PowerShell, disable scanning, C2; (B) personalized cloud exe (company-org-filters-update-victim.exe), persistence, headless Edge, PetitPotam NTLM relay toward a DC. Unit 42 says their MDR blocked that DC attempt. Cortex: collaboration-tool phish 42% of phish alerts in those four months (was 30%).
This is not the 2 September Microsoft “impersonating IT support” Daily Top already in this archive — Microsoft’s write-up is a later, distinct hands-on-keyboard campaign. Same theater, different vendor paper. Secondary outlets that map Spring Ring to APT29/Muddled Libra are not Unit 42’s attribution in the primary post; treat those as UNVERIFIED.
What happened
Default “chat with anyone” turned the helpdesk script into a domain-relay path.
Why it matters
Email filters never see a Teams call. PetitPotam is a 2021 bug with a 2026 delivery system.
What is confirmed vs not
CONFIRMED Unit 42 counts, TTPs, DC-relay attempt blocked in their telemetry.
NOT: APT29 as Unit 42’s call.
What defenders should do
- Restrict Teams external access; no unsolicited IT tenants.
- Helpdesk does not initiate Quick Assist on inbound Teams.
- PetitPotam mitigations on DCs still matter.
RWP assessment
Confidence: High on Unit 42. Keep it separate from the Microsoft 2 September post.
Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-31 and was added to the RWP archive on 2026-09-07.
Sources
- Unit 42 — Spring Ring voice phishing in Microsoft Teams
- Help Net Security — Spring Ring Teams vishing
- Dark Reading — Spring Ring on Teams users