Bottom line: Microsoft Teams users should immediately disable voice and video calls to prevent exploitation.
What's happening: The Spring Ring campaign, attributed to Iranian actors, exploits vulnerabilities in Microsoft Teams to deliver voice phishing attacks, which have been detected in the United States, United Kingdom, and India. In February 2023, attackers used a vulnerability (CVE-2022-25901) with a CVSS score of 9.8 to gain unauthorized access to Microsoft Teams. The attacks target enterprise domain controllers, which are then compromised using a custom-built malware.
What to do: Security leaders should immediately implement a voice call and video conference restriction policy to prevent exploitation, and conduct regular security awareness training for Microsoft Teams users to educate them on the risks of voice phishing. TOTAL: 146 words