The Phishing Landscape Has Shifted Again
Phishing and social engineering attacks continue to evolve at a pace that outstrips many organizations' defenses. In early September 2026, we're seeing three distinct trends converge: voice phishing (vishing) campaigns targeting collaboration platforms, sophisticated fake software distribution networks, and trojanized mobile apps promoted through legitimate advertising channels. Each represents a different attack vector, but all share a common thread—they exploit trust in familiar brands and workflows.
Let's break down what's happening right now, the specific red flags your team needs to recognize, and the concrete defenses that actually work.
Vishing Attacks Target Microsoft Teams Users
A threat operation dubbed "Spring Ring" is actively targeting Microsoft Teams users with voice-based social engineering attacks. The attackers are using vishing techniques to compromise collaboration suite users, then pivoting to remote session access, malware distribution, and infrastructure takeover.
This represents a maturation of business email compromise (BEC) tactics. Rather than relying solely on email, attackers are moving into voice and video channels where users may have less security awareness training and fewer technical controls.
Red Flags for Teams-Based Vishing
- Unexpected voice or video calls from external contacts claiming to be from IT, vendors, or partners
- Urgent requests for credentials, MFA codes, or remote access during calls
- Pressure tactics that discourage verification through alternative channels
- Requests to install software or grant permissions during the call
- External participants in calls that were supposed to be internal-only
Concrete Defenses
- Configure Microsoft Teams external access policies to require explicit approval for external communications
- Train staff to independently verify any caller's identity using known contact information, never information provided during the suspicious call itself
- Implement a clear escalation path for suspicious calls that doesn't rely on the communication channel being attacked
- Enable call recording and logging for compliance and forensic purposes
- Use conditional access policies to restrict sensitive actions based on device compliance and location
Fake Software Installers Weaponize Trust in Popular Brands
An active malware campaign is distributing fake software installers through bogus download websites that impersonate trusted vendors. These malicious installers specifically disable Windows Update and weaken Microsoft Defender protections, creating a persistent foothold for further compromise.
The campaign targets users searching for popular software, leveraging search engine optimization and paid advertising to position malicious sites above legitimate sources.
How the Attack Works
- User searches for legitimate software (productivity tools, utilities, media players)
- Attacker-controlled site appears in search results, often mimicking the real vendor's branding
- Downloaded installer appears functional but contains malicious payloads
- Malware disables security updates and weakens endpoint protection
- System becomes vulnerable to secondary infections and persistent access
Red Flags for Fake Installers
- Download sites with URLs that don't exactly match the official vendor domain
- Installers that request unnecessary administrative privileges
- Software that asks to disable antivirus or security tools during installation
- Download pages with poor grammar, layout inconsistencies, or suspicious ads
- Installers significantly smaller or larger than expected file sizes
Concrete Defenses
- Maintain an approved software list with verified download sources
- Use centralized software deployment tools rather than allowing end-user downloads
- Implement application allowlisting where feasible
- Configure endpoint protection to alert on attempts to modify Windows Update or security services
- Verify digital signatures on all downloaded executables before running
- Use DNS filtering to block known malicious domains and newly registered domains
StreamRat Android Trojan Spreads via Meta Advertising
Cybersecurity researchers have identified StreamRat, a new Android banking trojan promoted to Spanish-speaking users through fake television-streaming campaigns on Meta platforms. The malware achieves near-complete device control once installed.
This attack demonstrates how threat actors are increasingly using legitimate advertising platforms to reach targets at scale. The social engineering here is straightforward: offer desirable content (streaming TV) through what appears to be a normal app installation.
Red Flags for Malicious Mobile Apps
- Apps promoted through social media ads rather than official app stores
- Apps requesting excessive permissions unrelated to their stated function
- Streaming or media apps from unknown publishers
- Apps requiring installation from unknown sources or APK files
- Offers that seem too good to be true (free access to premium content)
Concrete Defenses for Mobile Security
- Implement mobile device management (MDM) with policies restricting app installation sources
- Require all business-related mobile devices to use only official app stores
- Enable Google Play Protect or equivalent on all Android devices
- Train users to recognize social media advertising scams
- Use mobile threat defense solutions for high-risk users
- Implement network-level filtering that can detect mobile malware communication patterns
The Common Thread: Exploiting Legitimate Channels
What ties these three campaigns together is their abuse of channels users have been trained to trust. Microsoft Teams is a business tool. Software installers are necessary for productivity. Social media ads from major platforms seem vetted. Attackers understand that users make different risk calculations based on context.
The defense, therefore, must be context-aware verification. Every request for sensitive information, software installation, or permission grant should trigger a verification step that uses a different channel than the one making the request.
Building Organizational Resilience
Beyond technical controls, organizations need cultural and procedural defenses:
- Normalize verification. Make it socially acceptable—even expected—to pause and verify unusual requests
- Eliminate time pressure as an excuse. Real emergencies are rare; most "urgent" requests are social engineering
- Test your people. Regular phishing simulations should include vishing and smishing scenarios, not just email
- Maintain incident response muscle memory. Users should know exactly what to do when they suspect compromise
Additional September 2026 Threats to Monitor
While not strictly phishing, two other campaigns demonstrate the breadth of current social engineering:
- A Russian national was indicted for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware, demonstrating the scale possible with targeted phishing
- 153 million driver's license images are being sold on the dark web, likely from a breach of IDScan.net, providing attackers with identity verification materials for more convincing social engineering
The second item is particularly concerning because it provides attackers with the exact documentation needed to pass identity verification checks, making social engineering attacks significantly more convincing.
Take Action Now
Review your organization's defenses against these specific attack vectors this week. Update your security awareness training to include vishing scenarios. Audit your software installation procedures. Verify your mobile device policies.
If you need help assessing your organization's resilience to modern phishing and social engineering attacks, Vici Tech Solutions offers comprehensive penetration testing and security assessments that include social engineering components tailored to your specific threat landscape.