Executive Summary
Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. Our telemetry reveals that this operation targeted more than 150 employees across at least 10 companies in various industries. We call this activity Spring Ring.
What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC).
We provide a technical breakdown of this operation’s attack lifecycle across two observed campaigns, both illustrating vishing manipulation that resulted in the attempted payload delivery via two distinct attack vectors.
These two campaigns demonstrate the weaponization of communication platforms as identity becomes a primary attack vector.
Palo Alto Networks customers are better protected from the threats described here through the following products and services:
- Advanced URL Filtering and Advanced DNS Security
- Cortex XDR and XSIAM
- Cortex Advanced Email Security
- Cortex Cloud Identity Threat Detection
- Idira Threat Detection and Response (ITDR)
- Idira Endpoint Privileged Manager (EPM)
- Idira Privileged Access Management (PAM)
- Idira Secure Infrastructure Access (SIA)
If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.
| Related Unit 42 Topics | Phishing, Identity, Social Engineering |
Overview: The Trust Gap
Spring Ring’s activity mirrors a broader trend in the threat landscape toward social engineering campaigns. According to our recently published Insights blog, threat actors have increasingly moved away from traditional phishing techniques toward trusted collaboration tools.
In the first four months of 2026, phishing alerts from collaboration tools represented 42% of all phishing alerts in Cortex, up from 30% of all phishing alerts in the preceding four months. In addition, according to KnowBe4’s Phishing Threat Trends Report, Teams-based attacks rose by 41% [PDF] between October 2025 and March 2026. They note that this surge is driven by attackers exploiting the platform's default “Chat with Anyone” feature to initiate direct chats with users outside their organization.
Previous Teams-based attacks, such as those by Cloaked Ursa (aka APT29), focused on credential harvesting and group chat-based social engineering. They often relied on malicious links or fake Entra ID tenants to appear legitimate.
Spring Ring’s approach relies on active human voice interaction. In this way, attackers can evade detection without a software exploit. Instead, they rely on exploiting the trust that employees place in software as a service (SaaS) collaboration platforms.
SaaS Applications: The New High-Value Target
SaaS applications are essential for business operations, storing an organization’s most critical and sensitive data. Unlike email, where users are trained to look for external sender banners or suspicious links, communications platforms provide a closed loop that attackers exploit by:
- Leveraging platform trust: People are more likely to engage with a message from a help desk identity than a random email from an external domain
- Exploiting human interaction: A professional voice on an audio call creates a level of trust that is difficult to manufacture in text, making the victim more susceptible to manipulation
- Bypassing the monitoring gap: Voice calls are often less monitored, recorded or documented than employees’ digital file operations or email histories, providing attackers with a secluded environment to execute their lures
The Evolution of Collaboration Attacks
The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow. This shift moves the attack from a passive click-and-harvest model to a real-time engagement.
Attackers can then pivot based on the victim's responses. Once the trust gap is crossed, the path to domain-level privileges via open-source tools like PetitPotam is short.
Figure 1 shows an example of the warning that Teams users get when an external identity creates a chat with them.
Anatomy of Spring Ring: How Attackers Masquerade as Internal Support
The Spring Ring campaigns are a coordinated operation that relies on impersonating corporate IT structures. Attackers can drop their lures into a victim's primary communication channel using external Microsoft Teams accounts.
The Discovery: Spotting the Pattern
Our investigation into this activity began after the release of a new detection suite for Microsoft Teams. By monitoring these alerts, we identified a suspicious pattern of chat creation across multiple tenants. Further investigation into these alerts led to the initial discovery of 26 distinct identities approaching targets across different organizations.
The Initial Hook: Crafted Personas and Domains
The attack begins with creating a Microsoft Teams chat using identities designed to mirror legitimate internal support units. The attackers opt for professional, urgency-focused display names such as help desk, IT assistance or support staff.
To strengthen the impression of legitimacy, the attackers operate from external .onmicrosoft[.]com tenants. These are meant to resemble legitimate corporate infrastructure. They are used by attackers to provision Microsoft 365 tenants. The subdomains are controlled by the adversaries.
Threat actors frequently abuse or subvert legitimate products for malicious purposes. This does not indicate that the product itself is flawed or compromised. Unit 42 has no evidence of any compromise or vulnerability within Microsoft's product related to this campaign.
Here are examples of these subdomains:
- ithelp@InternalSystemsDaily[.]onmicrosoft[.]com
- HelpDesk@ITProtectionDepartment[.]onmicrosoft[.]com
- itadmin@MandatoryNetworkMonitoring[.]onmicrosoft[.]com
- Internal@InternalUSAHelpDeskIT[.]onmicrosoft[.]com
- ithelpdesk@CertifiedUpdateNetwork[.]onmicrosoft[.]com
In some instances, the actors went beyond generic role names and used specific names to increase the perceived authenticity of the technician on the other end of the line:
- patrick[..]@infrastructureopsdesk.onmicrosoft[.]com
- robert[..]@systemdeploymentcenter.onmicrosoft[.]com
- clara[..]@systemsupportoperations.onmicrosoft[.]com
Names have been partially redacted because the attackers used specific names of legitimate industry personnel. The use of these names does not indicate a compromise of their accounts.
After the chat is created, the attacker initiates a voice call (the vishing element) to coerce the victim. After establishing a connection with what the victim believes is their own IT department, the attacker guides targeted employees through the steps to grant them remote control or execute malicious payloads.
The Scale of Spring Ring
Our telemetry reveals that these attackers often make several attempts — including leaving voicemails — before establishing a connection. We observed the attackers engaging victims in calls that varied in duration:
- Many calls last only a few seconds or they are missed by the victim as the attacker cycles through targets
- Successful calls often last between 10 and 15 minutes
Figure 2 shows several vishing attempts made by the same attacker identity on six different targets, with different conversation durations.
The reach of these campaigns is significant:
- More than 10 tenants were attacked: We observed the campaigns targeting many organizations across different industries
- More than 150 targets were approached: The attackers contacted more than 150 individual employees
- Persistent activity: We tracked the campaigns since January 2026 over a period of several weeks. According to our telemetry, these campaigns were active up until April 2026.
Technical Deep Dive: The RMM and Custom Dropper Combination
Once the attacker establishes trust through the initial vishing call, the Spring Ring campaigns transitioned into a technical execution phase designed to gain a permanent foothold. We provide a detailed analysis of two campaigns (Campaign A and Campaign B) that both began with a Microsoft Teams lure. They then diverged in their payload delivery, tool complexity and post-compromise activities.
Figure 3 shows the full attack flow of the two campaigns' attack methods.
Campaign A: From Support Tools to Obfuscated Payloads
In Campaign A, the attacker used a bring-your-own-tool approach, luring the victim to execute legitimate RMM software. The attacker posing as a technician walked the employee through launching built-in Windows tools like Quick Assist or downloading third-party RMM software. Once the RMM tool ran, the attacker could request remote control of the victim’s machine.
After gaining remote control, the attacker performed a series of basic enumeration commands to gain information on the host and domain. We observed them executing:
|
1 2 |
whoami /groups net group /dom |
After confirming the environment's value, the attacker pivots to payload delivery. The attacker used a PowerShell command line to download an obfuscated PowerShell-based remote access Trojan (RAT) from the attacker-controlled domain, san-sid[.]com. This malware used variable manipulations and arithmetic obfuscation designed to evade automated security analysis and sandbox detection.
By leveraging advanced AI and pattern-matching algorithms, we were able to de-obfuscate the RAT. We started by stripping away anti-analysis bloat from the code that was used to cause a time-out for deobfuscation tools.
The actual payload is a tiny, nine-line command and control (C2) stager. The script disables Antimalware Scan Interface (AMSI) via the amsiInitFailed flag and executes a test scan to verify the bypass. Upon verification, the script encrypts host data and beacons out to san-sid[.]com to download and execute further payloads.
Figure 4 shows a snippet of the obfuscated PowerShell-based RAT.
This campaign was blocked by automated Cortex XDR Agent protections during the malware's execution phase.
Campaign B: The Tailored Cloud Execution Chain
The second campaign used a more customized delivery method. During the vishing call, the attacker directed the victim to a cloud endpoint. The attackers tailored the cloud infrastructure and filenames to match the targeted organization and the specific user, for example:
-org-filters-update-.s3.us-west-2.amazonaws[.]com
When the victim clicked a link containing their own company's name and downloaded -org-filters-update-[.]exe, it triggered an execution chain:
- Staging and persistence: The executable moved itself to the \Temp\ directory and spawned copies (e.g., vhlp-*.exe and scnr-*.exe) as a persistence mechanism
- Browser hijacking: The malware launched a hidden, headless instance of Microsoft Edge, and the attackers wrote to the disk and sideloaded an Edge extension
- Lateral movement and authentication coercion: The attackers used Python (C:\ProgramData\IntegrityData\python.exe) to initiate a lateral movement sequence:
- SMB scanning: Initiated port 445 traffic targeting internal servers
- NTLM authentication: Generated NTLM traffic targeting the organization's DC
- PetitPotam exploitation: The attacker attempted a PetitPotam attack to coerce the DC into authenticating back to an attacker-controlled machine. This NTLM relay attack was designed to grant the attacker domain-level privileges
After attempting to coerce the DC, the attacker's domain-takeover attempt was blocked by Unit 42 Managed Detection and Response.
Summary of Tactical Divergence
By comparing the two campaign paths, we can better understand the diversity of threats targeting collaboration platforms. Table 1 compares the campaigns' specific methods of attack.
| Feature | Campaign A | Campaign B |
| Initial Lure | Microsoft Teams vishing | Microsoft Teams vishing |
| Primary Delivery | RMM tools | Tailored hosting infrastructure executables |
| Stealth Mechanism | Obfuscated PowerShell | Headless Microsoft Edge and sideloaded extension |
| Lateral Movement | Basic enumeration only | PetitPotam NTLM relay |
Table 1. Comparing the two campaigns’ methods.
This comparison highlights an important point for defenders. A simple vishing hook can lead to either a standard malware infection, or to a serious domain-level breach if the attacker pivots to payload delivery.
Identifying Teams Impersonation and Identity-Based Anomalies
Recognizing campaigns like Spring Ring requires a strategy of profiling external and internal entity behaviors. The attackers behind these campaigns operate within a legitimate ecosystem, so detection hinges on identifying small anomalies in how external identities interact with your organization.
Profiling the Identity
The first line of defense is recognizing the markers of the external actor. Our research into these campaigns highlights several consistent patterns:
- Spoofed domain naming: Attackers mostly use external .onmicrosoft[.]com tenants that include keywords like internal, certified, network or infrastructure to project authority
- Persona mimicry: They use professional display names, like IT help desk or admin, to increase the perceived authenticity of the technician during vishing calls
- Infrastructure red flag: The source IP addresses for these connections often originate from commercial VPN services to mask the attacker's true location
Behavioral Metrics of the Interaction
Our researchers were able to identify key markers of Spring Ring activity by analyzing the metadata of these interactions, despite the deceptive nature of the attacker’s initial lures:
- The chat-to-call ratio: A primary indicator is the rapid transition from a 1:1 chat request to an unsolicited audio call
- Call curation profiling: Attackers cycle through targets quickly. We observed call patterns ranging from 30-second initial attempts to 15-minute sessions.
- Multiple approaches: These actors demonstrate high operational volume, often approaching 5-6 identities within a matter of minutes using one of their spoofed identities
Recognizing Post-Compromise Behavior
Upon a successful compromise, we observed endpoint activity characterized by:
- Atypical execution of RMM tools by users who do not require remote support
- Access to unknown links, including cloud storage URLs or other file hosting servers that victims might be lured to access
Organizations can identify the Spring Ring lifecycle before the attacker transitions from a chat to a domain-level attack, by profiling these signals, the origin of the tenant and the subsequent attack flow.
Figure 5 shows one example of a Cortex alert on a new suspicious conversation created in Microsoft Teams. This alert is based on behavioral and metadata analysis of a newly created chat.
Conclusion
The Spring Ring campaigns demonstrate a strategic pivot in social engineering, where attackers move beyond email phishing to enterprise collaboration tools. Attackers turn an important productivity tool into a conduit for domain-level exploitation, masquerading as internal help desk personnel through vishing calls.
This activity highlights an important shift in the security landscape. Identity is now a primary perimeter, and the platforms we rely on for daily communication are being weaponized.
Looking forward, attackers might further refine their ability to operate within SaaS ecosystems. These platforms are not just an initial access vector, they contain sensitive documentation, workflows and communication logs that could allow an adversary to advance their attack chain.
Our analysis of the Spring Ring operation reinforces several key lessons:
- Trusted SaaS applications are not inherently safe: Attackers exploit the confidence that employees place in communications platforms
- Attack vectors are simple and scalable: By using seemingly legitimate external tenants and professional vishing lures, attackers can target hundreds of employees across many industries with minimal friction
- Adaptability is key: Attackers are evolving their methods, shifting from basic credential harvesting to human-led lateral movement
As these threats evolve, organizations must prioritize user education regarding unsolicited external communication across collaboration platforms. Robust behavioral monitoring can help identify identity-based anomalies before they escalate to lateral movement.
Palo Alto Networks Protection and Mitigation
Palo Alto Networks customers are better protected from the threats discussed above through the following products:
- Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious.
- Cortex XDR and XSIAM can help prevent the execution of both known and unknown malware through Behavioral Threat Protection and machine learning powered by the Local Analysis module. Beyond stopping initial execution via malicious droppers, Cortex XDR actively halts post-exploitation activities, such as PetitPotam NTLM relay attacks, before adversaries can achieve lateral movement.
- Cortex Cloud Identity Threat Detection can help deliver real-time protection against identity-based threats across cloud providers, IdPs, and SaaS applications. Using advanced behavioral analytics on real-time telemetry, ITDR baselines access patterns to detect anomalies, track complex attack chains—such as the Spring Ring lifecycle and trigger automated responses to contain compromised credentials.
- The Cortex Advanced Email Security module can help extend the power of the Cortex platform into cloud-hosted email environments, providing a scalable, AI-driven layer for detection, investigation, and response. By automatically stopping email threats and malicious communications across enterprise environments, it provides seamless protection across one of your most vulnerable attack vectors.
- Idira Threat Detection and Response can help enable security teams to counter identity-based attacks targeting Idira Next Generation Identity (NGI) Platform and the identities it secures. Using near real-time detection, powered by CORA AI, and leveraging Idira’s visibility across multiple contexts (like PAM, authentication, SSO, cloud, endpoints, browsers, and more), Idira ITP can apply automated, tailored non-disruptive in-session response to contain and minimize potential identity-based threats.
- Idira Endpoint Privilege Manager can help enable enterprises to reduce risk, satisfy compliance, and streamline operations. It helps implement least privilege via policy-driven elevation and removal of standing admin rights, and blocks risky actions, such as execution of unvetted applications and access to memory of other processes, while providing audit-ready evidence and unified identity governance. Automation and consolidation improve efficiency and support Zero Trust strategies, strengthening security without slowing the business.
- Idira Privileged Access Management can help unify privileged access across human, machine, and agentic identities to secure cloud access across multi-cloud environments. Building on proven PAM, it delivers centralized secrets management alongside modern controls like Just-in-Time access and Zero Standing Privileges. This enforces consistent least-privilege security across on-premises, cloud, and SaaS targets.
- Idira Secure Infrastructure Access can help enforce Zero Standing Privileges (ZSP) through Just-in-Time (JIT) provisioning which grants temporary, tightly scoped access only as needed. Backed by continuous session recording and real-time command monitoring, SIA can detect high risk actions before an attacker compromises critical systems.
If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call:
- North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
- UK: +44.20.3743.3660
- Europe and Middle East: +31.20.299.3130
- Asia: +65.6983.8730
- Japan: +81.50.1790.0200
- Australia: +61.2.4062.7950
- India: 000 800 050 45107
- South Korea: +82.080.467.8774
Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance.
Indicators of Compromise
Attacker Identities Used in Vishing Attempts – Generic
- helpcenter@ithelpcenter365[.]onmicrosoft[.]com
- helpdesk@itprotectiondepartment[.]onmicrosoft[.]com
- helpdesk@newsystemmaintenance[.]onmicrosoft[.]com
- helpdesk@officedesk365[.]onmicrosoft[.]com
- helpdesk@officesecures[.]onmicrosoft[.]com
- helpdesk@tbcsschid[.]onmicrosoft[.]com
- internal@internalusahelpdeskIT[.]onmicrosoft[.]com
- it_assistance@teams0137[.]onmicrosoft[.]com
- it@infrastructurefirewall[.]onmicrosoft[.]com
- itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com
- itassistant@bilelonellc[.]onmicrosoft[.]com
- ithelp@certifiednetworksec[.]onmicrosoft[.]com
- ithelp@internalsystemsdaily[.]onmicrosoft[.]com
- ithelp@itprotectiondepartment[.]onmicrosoft[.]com
- ithelp@mandatorynetworkmonitoring.onmicrosoft[.]com
- ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com
- support@bilelonellc[.]onmicrosoft[.]com
Attacker Identities Used in Vishing Attempts – Usernames
Names have been partially redacted to protect the users associated with accounts that were impersonated by the attackers.
- andreas[..]@idigitalserviceoperation.onmicrosoft[.]com
- andrew[..]@hapsinfrastructureops.onmicrosoft[.]com
- brandon[..]@devsitoperationhub.onmicrosoft[.]com
- brian[..]@appssupportsys.onmicrosoft[.]com
- christopher[..]@adevpsitplatformops.onmicrosoft[.]com
- christopher[..]@itplatformops.onmicrosoft[.]com
- christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com
- clara[..]@systemsupportoperations.onmicrosoft[.]com
- daniel[..]@opsnetsupportit.onmicrosoft[.]com
- daniel[..]@apsitsupporthub.onmicrosoft[.]com
- emily[..]@apsitechsupportdesk.onmicrosoft[.]com
- eric[..]@appopshelp.onmicrosoft[.]com
- henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com
- james[..]@helpitsupportcore.onmicrosoft[.]com
- james[..]@itcoretechhelp.onmicrosoft[.]com
- jonathan[..]@itservicedesk.onmicrosoft[.]com
- justin[..]@techopshelpsupp.onmicrosoft[.]com
- kevin[..]@itopsupportdesk.onmicrosoft[.]com
- kevin[..]@netopsdeskhelp.onmicrosoft[.]com
- leon[..]@netcorevdapp.onmicrosoft[.]com
- lucas[..]@applicationoperationsunit.onmicrosoft[.]com
- martin[..]@syslanevdapp.onmicrosoft[.]com
- matthew[..]@supportopsupp.onmicrosoft[.]com
- michael[..]@appdeploymentservices.onmicrosoft[.]com
- michael[..]@infratechopsdesk.onmicrosoft[.]com
- michael[..]@itopsdeskhelp.onmicrosoft[.]com
- patrick[..]@infrastructureopsdesk.onmicrosoft[.]com
- rachel[..]@ioseccloudsupport.onmicrosoft[.]com
- rebecca[..]@infrastructureopsservice.onmicrosoft[.]com
- robert[..]@systemdeploymentcenter.onmicrosoft[.]com
- ryan[..]@apstechopsdeskdev.onmicrosoft[.]com
- ryan[..]@helpssupportcloudops.onmicrosoft[.]com
- ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com
- sarah[..]@secinfrahelpdesk.onmicrosoft[.]com
- sarah[..]@apsscloudopsdesk.onmicrosoft[.]com
- sarah[..]@helpitdevsupportops.onmicrosoft[.]com
- sarah[..]@itdevsupportops.onmicrosoft[.]com
- scott[..]@cloudinfrastr.onmicrosoft[.]com
- steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com
- thomas[..]@networkoperationsec.onmicrosoft[.]com
- thomas[..]@seqapsitsupportops.onmicrosoft[.]com
Infrastructure Used in Vishing Attempts (VPNs and Proxies)
- 193.32.248[.]251
- 193.138.7[.]142
- 185.65.134[.]209
- 178.130.47[.]46
- 5.181.3[.]106
- 2.56.172[.]214
- 185.234.67[.]53
- 45.8.157[.]185
- 80.66.72[.]215
- 136.0.20[.]6
- 185.213.155[.]226
- 185.155.99[.]161
- 92.118.232[.]131
- 45.182.189[.]80
- 185.65.133[.]51
- 45.33.22[.]47
Malicious Files From Post-Compromise Activity (Campaign A)
- SHA256 hash: 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b (obfuscated PowerShell payload)
File description: Obfuscated PowerShell RAT dropper downloaded via Invoke-WebRequest
- URL: hxxps[:]//san-sid[.]com/owners
Description: URL hosting obfuscated PowerShell payload used as RAT dropper
Cortex XDR Alerts and MITRE ATT&CK® Techniques
Table 2 lists the Cortex XDR alerts and the associated MITRE ATT&CK techniques these alerts detect.
| Alert Name | Alert Source | MITRE ATT&CK Technique |
| External user started a Microsoft Teams conversation | XDR Analytics, Identity Threats | Phishing (T1566) |
| External user created a Microsoft Teams conversation with suspicious operations | XDR Analytics, Identity Threats | Phishing (T1566) |
| External user added a link to a Microsoft Teams chat | XDR Analytics, Identity Threats | Phishing (T1566) |
| External user call via Microsoft Teams | XDR Analytics, Identity Threats | Phishing: Spearphishing Voice (T1566.004) |
| Rare process execution by user | XDR Analytics, UEBA | User Execution (T1204) |
| Rare process execution in organization | XDR Analytics, UEBA | User Execution (T1204) |
| Multiple rare process executions in organization | XDR Analytics, UEBA | User Execution (T1204) |
| A process connected to an atypical rare cloud resource | XDR Analytics | Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) |
| Uncommon local scheduled task created | XDR Analytics | Scheduled Task/Job (T1053) |
| A browser was forced to load an extension using a special command-line argument | XDR Analytics | Software Extensions: Browser Extensions (T1176.001) |
| Uncommon browser extension loaded | XDR Analytics | Software Extensions: Browser Extensions (T1176.001) |
| SMB traffic from non-standard process | XDR Analytics | Network Service Discovery (T1046) |
| Rare NTLM access by user to host | XDR Analytics, UEBA | Use Alternate Authentication Material (T1550) |
| Unusual Encrypting File System Remote Protocol call (EFSRPC) to domain controller | XDR Analytics, UEBA | Forced Authentication (T1187)
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001) |
| Possible authentication coercion to a sensitive server | XDR Analytics, UEBA | Forced Authentication (T1187)
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001) |
| Possible Distributed File System Namespace Management (DFSNM) abuse | XDR Analytics | Forced Authentication (T1187)
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001) |
| Possible authentication coercion | XDR Analytics, UEBA | Forced Authentication (T1187)
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001) |
Table 2. Cortex XDR alerts and MITRE techniques.
Additional Resources
- When “Hi, This Is IT” Comes Through Microsoft Teams – Unit 42, Palo Alto Networks
- Cortex ITDR: Cyber Threats in Microsoft Teams and Their Detection – Palo Alto Networks
- Quick, You Need Assistance! – Fieldeffect
- PetitPotam – by topotam on GitHub
- APT29 Phishing Attacks via Microsoft Teams: Tactics, Techniques, and Prevention – InsiderSecurity
- Phishing Threat Trends Report [PDF] – KnowBe4
- Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook – Microsoft
