Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Microsoft Teams

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

Sophos tracks the campaign as STAC4749 and says it targeted dozens of organizations between February and June 2026.

At least three of these intrusions led to the deployment of Chaos ransomware, with one attack going from initial access to encrypting files in less than 17 hours.

image

Sophos says about 95% of the attacks targeted organizations in Canada (50%) and the United States (45%).

The threat actors targeted organizations across numerous sectors, with services, manufacturing, energy, and construction and engineering experiencing the largest number of attacks.

Microsoft Teams calls impersonate IT support

The attacks begin with external Microsoft Teams accounts impersonating IT helpdesk or support personnel in Teams chats and voice calls to targeted employees.

Calls observed by Sophos lasted between 90 seconds and more than 20 minutes, although most were completed in approximately two to two-and-a-half minutes.

In past Microsoft Teams social engineering attacks, threat actors would create their own tenants on Microsoft's onmicrosoft.com domain to initiate communication.

The STAC4749 campaign diverges from past campaigns by creating IT-themed domains under the ".top" top-level domain. Examples of these domains shared by Sophos are sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top.

The attackers paired these domains with fake IT support people using the names Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell, who appear to use specific domains tied to those aliases.

The goal of the calls was to convince employees to launch a remote support session using Microsoft Quick Assist or install another remote monitoring and management tool.

Sophos says the attackers initially preferred Quick Assist and used the cloud-based RemSupp remote management tool when Quick Assist was unavailable or blocked.

However, the threat actors later began primarily using RemSupp beginning in April, potentially because it was less likely to be included in corporate application blocklists.

After gaining remote access to employees' devices, the attackers used PowerShell to ultimately download a backdoor into the compromised user's %AppData% folder.

The malware profiled the system, established persistence, and provided continued remote access to the attackers.

To make the persistence mechanisms appear legitimate, malicious registry entries were disguised as Realtek and Windows audio components, using names such as "Realtek HD Audio," "Realtek Audio UHD," and "WinAudio life2."

In incidents that later led to Chaos ransomware deployment, the attackers also installed remote access software such as DWAgent or AnyDesk for backup access to systems on the network. They also attempted to enable Remote Desktop Protocol on compromised devices to move laterally between systems.

The Sophos report says the attackers continually modified the attack chain between February and May, changing malware filenames, persistence mechanisms, and deployment methods to avoid detection.

STAC4749's evolution of attack techniques
STAC4749's evolution of attack techniquesSource: Sophos

Linked to Chaos Ransomware

At least three STAC4749 compromises ultimately led to Chaos ransomware attacks, with at least one case where the attackers likely stole data before deploying the ransomware.

Sophos says that when the ransomware was deployed, it encrypted files simultaneously across compromised devices, with ransom notes named "readme.chaos.txt" created on affected systems.

Chaos ransom notes seen by BleepingComputer all show the same text claiming to have stolen data and warning that it would be leaked if a ransom is not paid.

Example of Chaos Ransomware notes
Example of Chaos Ransomware notesSource: BleepingComputer

In one incident seen by Sophos, less than 17 hours passed between the initial Microsoft Teams contact and the deployment of ransomware.

"Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates," Sophos said.

Sophos says the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal ransomware gangs. These ransomware operations were also spinoffs from the notorious Conti cybercrime syndicate.

Ransomware gangs and other threat actors have increasingly used Microsoft Teams to impersonate corporate IT support employees and convince targets to grant remote access to their devices.

In October 2024, Black Basta ransomware affiliates were observed flooding employees' inboxes with unsolicited emails before contacting them through Microsoft Teams as external users.

Microsoft Teams was also used in more recent attacks attributed to the Iranian state-sponsored MuddyWater hacking group, where the attackers allegedly used Chaos ransomware as a decoy to disguise a cyberespionage operation.

Sophos says it found no evidence connecting the new STAC4749 campaign to MuddyWater.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper
source: BleepingComputer