Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Key Points:
- Threat actors are impersonating IT support staff via Microsoft Teams calls to gain remote access to corporate devices, deploying Chaos ransomware in attacks primarily targeting North American organizations, with about 95% of attacks focused on Canada and the United States.
- The campaign, tracked by Sophos as STAC4749, targeted dozens of organizations across sectors such as services, manufacturing, energy, and construction between February and June 2026, with some attacks progressing from initial access to file encryption in under 17 hours.
- Attackers use fake IT-themed ".top" domains and aliases to initiate Teams calls, convincing employees to launch remote support sessions via Microsoft Quick Assist or the RemSupp tool, later installing backdoors and establishing persistence disguised as legitimate audio components.
- In cases leading to Chaos ransomware deployment, threat actors also installed remote access software and enabled Remote Desktop Protocol for lateral movement, continuously modifying their tactics to evade detection.
- Sophos links the Chaos ransomware-as-a-service operation to former members of BlackSuit and Royal gangs, noting the increasing use of Microsoft Teams for social engineering by ransomware groups and state-sponsored actors, although no connection was found between STAC4749 and the Iranian MuddyWater group.