Back to Intelligence

Spring Ring Teams Vishing Campaign + Gryxa AI-Built RMM Toolkit: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
September 30, 2026
10 min read

Two OTX pulses published 2026-09-30 paint a converging picture of how intrusion crews are industrializing social engineering and lower-skill tooling development in 2026.

Pulse 1 — Spring Ring (Unit 42 / AlienVault). Between January and April 2026, a coordinated voice phishing operation abused external Microsoft Teams accounts to impersonate corporate IT help desk staff. The operation targeted more than 150 employees across at least 10 companies. The attack chain is well established but executed at scale: adversaries initiate a Teams call (often preceded by email-bombing to manufacture urgency), socially engineer the victim into launching a remote monitoring and management (RMM) tool or custom PowerShell-based RAT, then pivot internally. Tags on the pulse — petitpotam, ntlm relay, domain controller — indicate the endgame: coerced NTLM authentication relayed against domain controllers for privilege escalation and domain compromise.

Pulse 2 — Gryxa toolkit (ReliaQuest / AlienVault). A threat actor with no meaningful development experience built the Gryxa intrusion toolkit with substantial assistance from an AI coding agent, deceiving the agent by claiming authorized testing. Gryxa functions as an RMM-style client with multiple persistence mechanisms, including scheduled tasks and Windows Event Subscriptions (WMI event subscription persistence, T1546.003), and operated across several hundred hosts. The associated infrastructure (gryxa.com, wirbe.com, seczio.com, sevrz.com and subdomains such as cdn.wirbe.com and mesh.wirbe.com) resembles a mesh/CDN-style C2 fabric consistent with RMM tooling.

Synthesis. Collectively these pulses demonstrate two converging trends: (1) identity-plane intrusion via collaboration platforms replacing phishing email as the primary initial access vector, and (2) AI-assisted development collapsing the skill barrier for building persistent RMM tooling. Both campaigns converge on the same operational model — legitimate-looking remote access tooling as the payload, persistence on the endpoint, and rapid escalation toward domain dominance. Enterprises should treat any unsanctioned RMM execution as a high-fidelity intrusion signal.

Threat Actor / Malware Profile

Spring Ring (Threat Actor: Unknown)

  • Distribution: External Microsoft Teams tenant accounts messaging and calling employees directly, impersonating IT help desk. Frequently paired with email bombing to justify the 'support call.'
  • Payload behavior: Victim is coached into executing an RMM installer or a custom PowerShell RAT dropped via san-sid.com staging infrastructure. Hands-on-keyboard activity follows within minutes of agent install.
  • C2 communication: RMM vendor infrastructure (legitimate signed binaries talking to vendor clouds), supplemented by actor-controlled staging domain san-sid.com.
  • Persistence: RMM agent service installation; secondary implants staged via PowerShell.
  • Privilege escalation: PetitPotam (MS-EFSRPC coercion) to force domain controller NTLM authentication, relayed to AD CS or LDAP for domain takeover (T1187 forced authentication, T1557 adversary-in-the-middle relay).

Gryxa (AI-Assisted Toolkit)

  • Distribution: RMM-style client deployed across several hundred hosts; delivery vector consistent with social engineering and loader staging.
  • Payload behavior: Modular client with remote command execution, file transfer, and reconnaissance capabilities characteristic of RMM clones.
  • C2 communication: Infrastructure spread across gryxa.com, wirbe.com, seczio.com, sevrz.com with role-separated subdomains — ui.gryxa.com (operator panel), mesh.wirbe.com (agent mesh relay), cdn.wirbe.com (payload delivery), debian.seczio.com (likely Linux build/update server). TLS over 443 blending with legitimate CDN traffic.
  • Persistence: Scheduled tasks (T1053.005) and Windows Event Subscriptions / WMI permanent event consumers (T1546.003) — the latter survives most AV remediation because the payload is registered in the WMI repository, not on disk.
  • Anti-analysis: AI-generated code produces non-standard, low-prevalence binaries with no shared lineage against known families, defeating hash and YARA-based detection; behavior-based detection is explicitly called out in the pulse as the required countermeasure. Known sample SHA256: 24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b.

IOC Analysis

IndicatorTypeAssociationOperationalization
san-sid.comdomainSpring Ring stagingBlock at DNS/proxy; retro-hunt proxy + DNS logs 90 days
24ab9fe5d5be...c1c5bSHA256Spring Ring / Gryxa-linked payloadBlock in EDR/AV; hash search across endpoint fleet
gryxa.com, ui.gryxa.comdomain/hostnameGryxa operator panelBlock; alert on any resolution — panel access implies operator presence
wirbe.com, cdn.wirbe.com, mesh.wirbe.comdomain/hostnameGryxa C2 mesh + payload CDNBlock; hunt beaconing patterns (regular-interval HTTPS)
seczio.com, debian.seczio.comdomain/hostnameGryxa update/build infraBlock; check Linux hosts for outbound connections
sevrz.comdomainGryxa supporting infraBlock; sinkhole if possible

How SOC teams should operationalize:

  • Domains/hostnames: Push to DNS protective resolver (e.g., RPZ), secure web gateway, and EDR network blocking. Because Gryxa infrastructure masquerades as CDN/mesh services, pair domain blocks with JA3/JA4 TLS fingerprinting where available.
  • Hashes: Import into EDR prevention lists (Microsoft Defender BlockAtFirstSeen + custom indicators, CrowdStrike custom IOA hash block). Hashes burn fast for AI-generated tooling — treat as point-in-time only.
  • Decoding/enrichment tooling: OTX DirectConnect API or the OTXv2 Python SDK for pulse pulls; MISP for indicator sharing; dnstwist/urlscan.io for infrastructure expansion off the seed domains; VirusTotal/ANY.RUN for detonation of the SHA256 sample.

Detection Engineering

YAML
---
title: Suspicious RMM or PowerShell RAT Execution Following Teams Interaction
id: 7f3a1c2e-9b4d-4e6a-a1c8-springring0001
status: experimental
description: Detects execution of RMM tooling installers or encoded PowerShell spawned in proximity to Microsoft Teams processes, consistent with Spring Ring help-desk vishing tradecraft.
author: Security Arsenal Threat Intel
logsource:
    category: process_creation
    product: windows
 detection:
    selection_teams_parent:
        ParentImage|endswith: '\ms-teams.exe'
    selection_rmm_binary:
        Image|endswith:
            - '\anydesk.exe'
            - '\teamviewer.exe'
            - '\screenconnect.exe'
            - '\netsupportmanager.exe'
            - '\quickassist.exe'
            - '\aeroadmin.exe'
            - '\rustdesk.exe'
    selection_ps_rat:
        Image|endswith:
            - '\powershell.exe'
            - '\pwsh.exe'
        CommandLine|contains:
            - ' -enc '
            - ' -ec '
            - 'FromBase64String'
            - 'DownloadString'
            - 'san-sid.com'
    condition: selection_teams_parent and (selection_rmm_binary or selection_ps_rat)
falsepositives:
    - Legitimate help desk pushing RMM via Teams chat (verify against change tickets)
level: high
tags:
    - attack.initial_access
    - attack.t1566
    - attack.t1219
    - attack.t1059.001
date: 2026/09/30
---
title: Gryxa Toolkit Persistence — Scheduled Task or WMI Event Subscription
id: 8a4b2d3f-0c5e-5f7b-b2d9-gryxa0000002
status: experimental
description: Detects persistence mechanisms associated with the Gryxa AI-built toolkit — scheduled task creation and WMI permanent event subscription registration.
author: Security Arsenal Threat Intel
logsource:
    category: process_creation
    product: windows
detection:
    selection_schtasks:
        Image|endswith: '\schtasks.exe'
        CommandLine|contains:
            - '/create'
            - '/sc onlogon'
            - '/sc onstart'
    selection_wmi_persistence:
        Image|endswith:
            - '\powershell.exe'
            - '\pwsh.exe'
            - '\wmic.exe'
            - '\mofcomp.exe'
        CommandLine|contains:
            - '__EventFilter'
            - 'CommandLineEventConsumer'
            - 'ActiveScriptEventConsumer'
            - '__FilterToConsumerBinding'
            - 'root\subscription'
    filter_legit_admin:
        CommandLine|contains:
            - 'Microsoft\Windows\'
            - 'SystemCenter'
    condition: (selection_schtasks or selection_wmi_persistence) and not filter_legit_admin
falsepositives:
    - Enterprise management tooling (SCCM, Intune) creating tasks — baseline and tune
level: high
tags:
    - attack.persistence
    - attack.t1053.005
    - attack.t1546.003
date: 2026/09/30
---
title: Gryxa C2 Infrastructure DNS Resolution
id: 9b5c3e4a-1d6f-6a8c-c3e0-gryxa0000003
status: experimental
description: Detects DNS queries to known Gryxa toolkit command-and-control and staging infrastructure identified in OTX pulse reporting.
author: Security Arsenal Threat Intel
logsource:
    category: dns
    product: windows
detection:
    selection:
        query|contains:
            - 'gryxa.com'
            - 'wirbe.com'
            - 'seczio.com'
            - 'sevrz.com'
            - 'san-sid.com'
    condition: selection
falsepositives:
    - None expected — these domains have no legitimate enterprise use
level: critical
tags:
    - attack.command_and_control
    - attack.t1071.001
date: 2026/09/30
KQL — Microsoft Sentinel / Defender
// Hunt: Spring Ring vishing + Gryxa RMM toolkit activity — Microsoft Sentinel
// 1) DNS/network connections to known C2 and staging infrastructure
let BadDomains = dynamic(["san-sid.com","gryxa.com","wirbe.com","seczio.com","sevrz.com","cdn.wirbe.com","mesh.wirbe.com","ui.gryxa.com","debian.seczio.com"]);
let NetworkHits =
    DeviceNetworkEvents
    | where TimeGenerated > ago(30d)
    | where RemoteUrl has_any (BadDomains)
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort;
// 2) RMM tooling or encoded PowerShell spawned by Teams (Spring Ring tradecraft)
let RMMList = dynamic(["anydesk.exe","teamviewer.exe","screenconnect.exe","quickassist.exe","rustdesk.exe","aeroadmin.exe","netsupportmanager.exe"]);
let TeamsSpawned =
    DeviceProcessEvents
    | where TimeGenerated > ago(30d)
    | where InitiatingProcessFileName =~ "ms-teams.exe"
    | where FileName in~ (RMMList)
       or (FileName in~ ("powershell.exe","pwsh.exe") and ProcessCommandLine has_any ("-enc","-ec ","FromBase64String","DownloadString","san-sid.com"))
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256;
// 3) WMI event subscription persistence (Gryxa)
let WMIPersistence =
    DeviceProcessEvents
    | where TimeGenerated > ago(30d)
    | where ProcessCommandLine has_any ("__EventFilter","CommandLineEventConsumer","ActiveScriptEventConsumer","__FilterToConsumerBinding","root\\subscription")
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine;
// 4) Known malicious hash
let HashHits =
    DeviceProcessEvents
    | where SHA256 == "24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b"
    | project TimeGenerated, DeviceName, FileName, FolderPath, SHA256;
union NetworkHits, TeamsSpawned, WMIPersistence, HashHits
| sort by TimeGenerated desc
PowerShell
# Security Arsenal — Spring Ring / Gryxa IOC & Persistence Sweep
# Run as Administrator on suspect endpoints (or deploy via GPO/Intune/EDR live response)

$ErrorActionPreference = 'SilentlyContinue'
$Report = @()

# --- 1) DNS cache check for known C2 / staging domains ---
$BadDomains = @('san-sid.com','gryxa.com','wirbe.com','seczio.com','sevrz.com',
                'cdn.wirbe.com','mesh.wirbe.com','ui.gryxa.com','debian.seczio.com')
$DnsHits = Get-DnsClientCache | Where-Object { $e = $_.Entry; $BadDomains | Where-Object { $e -like "*$_*" } }
if ($DnsHits) { $Report += [pscustomobject]@{Check='DNS Cache'; Finding=($DnsHits | Out-String)} }

# --- 2) Active connections to Gryxa-linked infrastructure ---
$ConnHits = Get-NetTCPConnection -State Established |
    Where-Object { $_.RemotePort -in 443,8443,8080 } |
    ForEach-Object {
        $proc = Get-Process -Id $_.OwningProcess
        try { $r = Resolve-DnsName $_.RemoteAddress -ErrorAction Stop } catch { $r = $null }
        if ($r -and ($BadDomains | Where-Object { $r.NameHost -like "*$_*" })) {
            [pscustomobject]@{Check='Network'; Finding="$($proc.ProcessName) ($($proc.Id)) -> $($r.NameHost) [$($_.RemoteAddress):$($_.RemotePort)]"}
        }
    }
if ($ConnHits) { $Report += $ConnHits }

# --- 3) Scheduled tasks persistence (Gryxa) ---
$SuspiciousTasks = Get-ScheduledTask | Where-Object {
    $_.TaskPath -notlike '\Microsoft\*' -and
    ($_.Actions.Execute -match 'powershell|pwsh|cmd|rundll32|mshta|wscript' -or
     $_.Actions.Arguments -match '-enc|-ec |FromBase64String|http')
}
if ($SuspiciousTasks) {
    $Report += [pscustomobject]@{Check='ScheduledTasks'; Finding=($SuspiciousTasks | Select-Object TaskName,TaskPath,@{n='Action';e={$_.Actions.Execute + ' ' + $_.Actions.Arguments}} | Out-String)}
}

# --- 4) WMI event subscription persistence (Gryxa T1546.003) ---
$WmiFilters   = Get-WmiObject -Namespace root\subscription -Class __EventFilter
$WmiConsumers = Get-WmiObject -Namespace root\subscription -Class CommandLineEventConsumer
$WmiConsumers += Get-WmiObject -Namespace root\subscription -Class ActiveScriptEventConsumer
if ($WmiFilters -or $WmiConsumers) {
    $Report += [pscustomobject]@{Check='WMI Persistence'; Finding=($WmiConsumers | Select-Object Name,CommandLineTemplate,ScriptText | Out-String)}
}

# --- 5) Known malicious hash sweep (common staging locations) ---
$TargetHash = '24AB9FE5D5BE62D3BF055A0CA4508E8BCA2996B6D78649DCE8145D8A27BC1C5B'
$Paths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:ProgramData","$env:USERPROFILE\Downloads")
foreach ($p in $Paths) {
    Get-ChildItem $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
        if ((Get-FileHash $_.FullName -Algorithm SHA256).Hash -eq $TargetHash) {
            $Report += [pscustomobject]@{Check='Hash Match'; Finding="MALICIOUS FILE: $($_.FullName)"}
        }
    }
}

# --- 6) Unsanctioned RMM tooling installed ---
$RmmNames = 'AnyDesk','TeamViewer','ScreenConnect','RustDesk','AeroAdmin','NetSupport','Gryxa'
$Installed = Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*,
             HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* |
    Where-Object { $n = $_.DisplayName; $RmmNames | Where-Object { $n -like "*$_*" } } |
    Select-Object DisplayName, InstallDate
if ($Installed) { $Report += [pscustomobject]@{Check='RMM Installed'; Finding=($Installed | Out-String)} }

# --- Output ---
if ($Report) {
    Write-Host "[!] FINDINGS on $env:COMPUTERNAME" -ForegroundColor Red
    $Report | Format-List
    $Report | Export-Csv ".\ioc_sweep_$env:COMPUTERNAME.csv" -NoTypeInformation
} else {
    Write-Host "[+] Clean: $env:COMPUTERNAME — no Spring Ring / Gryxa indicators found." -ForegroundColor Green
}

Response Priorities

Immediate (0–4 hours)

  • Block all listed domains (san-sid.com, gryxa.com, wirbe.com, seczio.com, sevrz.com + subdomains) at DNS resolver, web proxy, and EDR network protection; add the SHA256 to EDR block lists.
  • Deploy the Sigma rules and run the KQL hunt across the last 30 days; run the PowerShell sweep on any host with Teams-spawned child processes.
  • Alert the service desk: no legitimate IT staff will ever initiate an unsolicited Teams call asking users to install software. Stand up a verbal duress/verification phrase.

24 Hours

  • For any confirmed Spring Ring victim: force password reset, revoke all sessions and refresh tokens (Teams/Entra ID), and check for newly registered MFA methods or inbox rules — vishing intrusions frequently pair with credential theft.
  • Audit AD CS and domain controller logs for PetitPotam-style EFSRPC coercion (Event ID 4688 on DCs, abnormal NTLM authentications) and NTLM relay attempts; hunt for unexpected certificate enrollments.
  • Inventory every RMM tool installed fleet-wide; uninstall anything not on the approved list and treat hosts with unsanctioned RMM as compromised pending triage.
  • If Gryxa persistence is found (WMI subscriptions or scheduled tasks), pull the WMI repository artifacts before rebuilding — mofcomp-registered consumers survive file deletion.

1 Week

  • Restrict external Teams communications: disable or tightly allowlist external tenant federation, and block inbound calls/chats from unmanaged tenants by policy.
  • Implement an application control policy (WDAC/AppLocker) blocking unauthorized RMM binaries by publisher/path; alert on Quick Assist usage outside the IT group.
  • Mitigate NTLM relay exposure: enable LDAP signing + channel binding on DCs, require EPA on AD CS web enrollment, disable NTLMv1, and restrict EFSRPC via the PetitPotam hardening guidance.
  • Add behavior-based detections (not hash-based) for AI-generated tooling: WMI event subscription creation, non-Microsoft scheduled tasks invoking script interpreters, and beacon-interval HTTPS to low-reputation domains.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.