Skip to content

Vishing over Microsoft Teams leads to Chaos ransomware deployment

The point: A vishing campaign exploits Microsoft Teams for remote access extortion and leads to Chaos ransomware encryption in at least three cases within under 17 hours.

Attackers impersonate IT support through external Microsoft Teams accounts and gain remote access to corporate devices. Sophos documents a campaign (STAC4749) between February and June 2026 with at least three cases in which the access led to the deployment of Chaos ransomware.

Sophos tracks the campaign under the designation STAC4749 and observed attacks between February and June 2026 on dozens of North American organizations. Approximately 95 percent of the attacks targeted companies in Canada and the United States, affecting service organizations as well as organizations from the manufacturing, energy, and construction and engineering sectors. The attackers use external Microsoft Teams accounts to pose as IT helpdesk employees in chats and calls. The observed calls lasted between 90 seconds and more than 20 minutes, but most ended after approximately two to two and a half minutes.

The attackers registered their own domains with the .top extension and used fictitious names of alleged support staff – for example sequrityupdate.top or system-connect.top. The aim of the calls was to persuade employees to initiate a remote support session via Microsoft Quick Assist or another remote support tool. Until April 2026, the attackers preferred Quick Assist, but then increasingly switched to the cloud tool RemSupp, presumably because this tool is less frequently captured by corporate blocklists.

After obtaining remote access, the attackers loaded a backdoor via PowerShell into the user’s AppData directory, which analyzed the system and secured persistent remote access. The associated registry entries were disguised as Realtek or Windows audio components. In cases that led to ransomware deployment, the attackers additionally installed tools such as DWAgent or AnyDesk as backup access and attempted to enable Remote Desktop access to move laterally within the network.

At least three documented compromises resulted in the deployment of Chaos ransomware, in at least one case following prior data theft. The encryption occurred on all compromised devices nearly simultaneously, accompanied by ransom demands in files named readme.chaos.txt. In one observed case, less than 17 hours elapsed between the initial Teams contact and complete encryption. The Chaos group is classified in the ransomware-as-a-service category and has existed since February 2025 according to Sophos. It is attributed to former members of the BlackSuit and Royal ransomware groups, which themselves originated from the Conti environment.


Source: www.it-daily.net · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification via Lumi News Pipeline v1.7.3.

Share on: