Skip to content

Attackers Exploit Microsoft Teams for Vishing Attacks and Chaos Ransomware Deployment

In brief: Attackers use vishing over Microsoft Teams to impersonate IT support and obtain remote access for ransomware deployment.

Threat actors pose as IT support in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware. The campaign targets organizations in North America.

Current attack campaigns demonstrate a classic vishing scenario (voice phishing) with modern use of collaboration tools: attackers initiate unsolicited Microsoft Teams calls and pose as IT support personnel. Through skillful social engineering, they guide targets to install remote-access tools or grant remote access to the affected device.

For CISOs, this attack vector is particularly noteworthy because Microsoft Teams is typically perceived as more trustworthy than external communication channels, lowering employee resistance to following instructions. Moreover, the use of internal corporate communication tools allows attackers to circumvent existing security structures that typically target external threat sources.

The primary objective of the attacks is the deployment of Chaos ransomware following successful compromise. This underscores the necessity of training measures to recognize identity verification, as well as a strictly structured remote-access policy that regulates the granting of remote access through technical controls and approval processes, not solely through verbal instructions.


Source: www.bleepingcomputer.com · Published July 30, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: