July 30, 20263 min read

Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Surge

Recent attacks leveraging Microsoft Teams to deploy Chaos ransomware have raised alarms. Threat actors impersonate IT support staff to gain access to corporate devices, affecting numerous organizations in North America.

A tense business meeting on Microsoft Teams

A series of vishing attacks on Microsoft Teams has led to significant Chaos ransomware deployments, as threat actors impersonate IT support staff to gain unauthorized remote access to corporate devices. These attacks, tracked by Sophos under the campaign name STAC4749, have predominantly targeted organizations in North America, raising serious alarms about cybersecurity vulnerabilities in remote work environments.

The Attack Strategy: Vishing and Impersonation

The STAC4749 campaign employs a clever yet alarming approach where attackers pose as IT helpdesk personnel during Microsoft Teams calls. According to recent reports, these calls can range from 90 seconds to over 20 minutes, with the average duration being around two to two-and-a-half minutes. This method represents a shift from previous social engineering tactics that involved creating entire tenants under Microsoft's domain. Instead, the attackers are using domains themed around IT support, such as sequrityupdate.top and supportsoft.top.

Technical Methods and Malicious Software

Once contact is established, the attackers aim to convince employees to either initiate a remote support session via Microsoft Quick Assist or install another remote support tool. While Initial preference was given to Quick Assist, the attackers shifted focus to the RemSupp remote management tool due to its lower chances of being blocked by corporate defenses. After gaining access, attackers utilize PowerShell to install backdoor malware in the user's %AppData% folder, allowing them to maintain long-term access.

Malware and Persistence

This malware operates stealthily to profile the system and establish persistence by making changes to the Windows registry, disguising malicious entries under legitimate-sounding names like Realtek HD Audio and WinAudio life2. Once the attackers set up their initial foothold, they may install additional remote access software, such as DWAgent or AnyDesk, giving them multiple avenues to infiltrate networks further.

Attack Evolution

The sophistication of the STAC4749 campaign lies in its ongoing evolution. Throughout the period of attacks from February to June 2026, insiders noticed modifications to malware filenames, persistence techniques, and overall deployment methods aimed at evading detection. This adaptability has made it increasingly challenging for organizations to counteract these emerging threats effectively.

Impact: Ransomware Deployment

At least three incidents linked to the STAC4749 campaign culminated in deploying Chaos ransomware, which encrypts files across multiple compromised devices almost simultaneously. Ransom notes, typically named readme.chaos.txt, have included threats of data leaks should the ransom not be paid. One alarming incident showcased a rapid transition from initial contact to ransomware deployment in less than 17 hours.

An example of ransomware notification on a compromised computer

Background on Chaos Ransomware

Chaos ransomware was first identified in 2025 and is believed to be operated by affiliates with connections to notable ransomware groups like BlackSuit and Royal, deriving from the notorious Conti cybercrime syndicate. Ransomware-as-a-service offerings from Chaos have recently gained prominence, making them a go-to choice for financially motivated attacks.

Precedents and Broader Threat Landscape

This increase in Microsoft Teams vishing attacks aligns with a broader trend observed in the cybersecurity landscape. Similar attack vectors have been used in past incidents, such as Black Basta ransomware affiliates using unsolicited emails as a precursor to Teams communication. Furthermore, individuals believed to be affiliated with state-sponsored hacking groups have also adapted Microsoft Teams for various malicious purposes, demonstrating the versatility and effectiveness of this platform amid modern cyber threats.

Key Takeaways

  • The STAC4749 campaign targets organizations primarily across the U.S. (45%) and Canada (50%) through Microsoft Teams:
  • Attackers impersonate IT support to gain access: Calls typically last less than three minutes.
  • Chaos ransomware has been rapidly deployed: In one situation, it occurred in less than 17 hours post-initial contact.
  • Adaptive malware techniques: The campaign has evolved to change malware names and to implement new persistence strategies.
  • Connections to a wider trend of Teams-related cyber threats: Earlier attacks have displayed similar methodologies.

Conclusion: The Urgency of Cybersecurity Measures

The rise of vishing attacks using Microsoft Teams as a conduit for Chaos ransomware highlights a pressing need for enhanced cybersecurity measures within organizations. As threat actors become more sophisticated, the onus is on security teams to implement proactive measures, including robust training programs that educate employees on recognizing suspicious communications. Although immediate solutions exist, long-term cybersecurity strategies must be prioritized to counteract such evolving threats in remote work environments.

Frequently Asked Questions

The STAC4749 campaign is a series of vishing attacks where threat actors impersonate IT support staff using Microsoft Teams to compromise corporate devices and deploy Chaos ransomware.
#Cybersecurity#Ransomware#Microsoft Teams#Vishing#Threat Intelligence