Microsoft Teams vishing attacks are being used to trick employees into granting remote access to their work devices, allowing attackers to deploy Chaos ransomware.

Sophos tracked the campaign as STAC4749 after it targeted dozens of organisations in North America between February and June 2026. At least three intrusions ended in ransomware, while one attack moved from initial contact to file encryption in under 17 hours.

Fake IT support calls target employees

The attackers posed as IT support staff through external Microsoft Teams accounts. They contacted employees through chats and voice calls, then tried to persuade them to start a remote support session.

Most calls lasted around two to two-and-a-half minutes. However, Sophos also observed calls ranging from 90 seconds to more than 20 minutes.

Around 95% of the attacks targeted Canadian and US organisations. Canada accounted for 50% of cases, while the US made up 45%.

The campaign hit several sectors. Services, manufacturing, energy, construction and engineering saw the highest number of attacks.

Attackers use IT-themed domains

Previous Teams social engineering campaigns often relied on attacker-controlled Microsoft tenants using the onmicrosoft.com domain. This campaign instead used IT-themed .top domains to appear more convincing.

Examples included sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top and supportsoft[.]top.

The attackers also used fake support identities, including Anthony Brooks, Dylan Harper, Ethan Parker and Jason Mitchell. These aliases appeared to be linked to specific malicious domains.

Their goal was to convince employees to use Microsoft Quick Assist or install remote monitoring and management software.

Remote access leads to persistent backdoors

Sophos said the group initially preferred Quick Assist. When it was unavailable or blocked, the attackers used the cloud-based RemSupp remote management tool.

From April onwards, RemSupp became the main option. Sophos suggested this may be because it was less likely to appear on corporate application blocklists.

After gaining access, the attackers used PowerShell to download a backdoor into the compromised user’s %AppData% folder. The malware collected system information, created persistence and gave the threat actors continued remote access.

To make the persistence entries look legitimate, the attackers used registry names resembling Realtek and Windows audio components. Examples included “Realtek HD Audio,” “Realtek Audio UHD” and “WinAudio life2.”

In attacks that later deployed ransomware, the group also installed DWAgent or AnyDesk for backup access. They also tried to enable Remote Desktop Protocol to move across the network.

Chaos ransomware deployed within 17 hours

At least three STAC4749 intrusions led to Chaos ransomware attacks. In one case, the attackers may have stolen data before encrypting files.

When Chaos ransomware was deployed, it encrypted files simultaneously across compromised devices. It also created ransom notes named readme.chaos.txt.

The notes claimed that data had been stolen and threatened to leak it unless a ransom was paid.

Sophos said one incident progressed from the initial Microsoft Teams contact to ransomware deployment in less than 17 hours. The short timeline indicates that the operation was financially motivated and may have either directly deployed ransomware or worked with affiliates.

No confirmed link to MuddyWater

Sophos said the Chaos ransomware-as-a-service operation has been active since at least February 2025. Researchers believe it may involve former members of the BlackSuit and Royal ransomware groups, both of which had links to the wider Conti cybercrime ecosystem.

Microsoft Teams has become an increasingly common channel for ransomware social engineering. Black Basta affiliates used similar tactics in 2024 after bombarding employees with emails before contacting them through Teams.

More recently, Iranian state-backed group MuddyWater was linked to Teams-based attacks where Chaos ransomware allegedly served as a distraction for espionage activity.

However, Sophos found no evidence connecting STAC4749 to MuddyWater.

Meta description: Microsoft Teams vishing attacks impersonate IT support staff to gain remote access and deploy Chaos ransomware in North America.


0 responses to “Microsoft Teams Vishing Attacks Lead to Chaos Ransomware”