Microsoft: Microsoft Teams Vishing Campaign Deploys Chaos Ransomware Through Fake IT Support Calls

Microsoft: Microsoft Teams Vishing Campaign Deploys Chaos Ransomware Through Fake IT Support Calls

Sophos Uncovers Microsoft Teams Vishing Campaign Deploying Chaos Ransomware

Sophos researchers identified a sophisticated voice phishing (vishing) campaign, tracked as STAC4749, targeting North American organizations between February and June 2026. The attackers impersonated IT support staff via Microsoft Teams chats and calls, tricking employees into granting remote access to corporate systems before deploying Chaos ransomware.

Attack Methodology

The threat actors used fake Microsoft Teams accounts with IT-themed usernames (e.g., AnthonyBrooks, DylanHarper) and domains like sequrityupdate[.]top and service-help[.]top to appear legitimate. Unlike previous campaigns that relied on spoofed onmicrosoft[.]com domains, STAC4749 employed custom .top domains to enhance credibility.

Once contact was established, the attackers persuaded victims to:

  • Launch Microsoft Quick Assist (early in the campaign)
  • Install RemSupp, a cloud-based remote support tool (used increasingly from April onward)
  • Enable Remote Desktop Protocol (RDP) by modifying Windows service configurations

Calls typically lasted 2–2.5 minutes, with some extending beyond 20 minutes, to convince employees of an urgent IT issue.

Post-Compromise Activity

After gaining access, the attackers deployed a modular malware toolkit to:

  • Conduct system discovery
  • Establish persistence
  • Execute commands
  • Move laterally across networks
  • Deploy Chaos ransomware in at least three confirmed incidents

In one case, ransomware encryption began in under 17 hours after the initial compromise, indicating a fast-moving, financially motivated operation.

Targeted Sectors & Impact

Nearly 95% of observed attacks focused on Canadian and U.S. organizations, with victims spanning:

  • Services
  • Manufacturing
  • Energy
  • Construction & Engineering
  • Intellectual property law firms

Sophos noted a rise in Teams-based vishing since January 2026, with similar tactics previously linked to Black Basta, 3 AM, and other ransomware groups. The campaign highlights the growing use of remote support tools as an initial access vector for ransomware operators.

Source: https://cyberpress.org/teams-vishing-chaos-ransomware/

Microsoft Security Response Center cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security-response-center

"id": "MIC1785399995",
"linkid": "microsoft-security-response-center",
"type": "Ransomware",
"date": "2/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Services',
                                     'Manufacturing',
                                     'Energy',
                                     'Construction & Engineering',
                                     'Intellectual Property Law Firms'],
                        'location': ['Canada', 'United States'],
                        'type': 'Organization'}],
 'attack_vector': ['Vishing (Voice Phishing)',
                   'Microsoft Teams',
                   'Remote Support Tools'],
 'data_breach': {'data_encryption': True},
 'date_detected': '2026-02-01',
 'description': 'Sophos researchers identified a sophisticated voice phishing '
                '(vishing) campaign, tracked as STAC4749, targeting North '
                'American organizations between February and June 2026. The '
                'attackers impersonated IT support staff via Microsoft Teams '
                'chats and calls, tricking employees into granting remote '
                'access to corporate systems before deploying Chaos '
                'ransomware.',
 'initial_access_broker': {'entry_point': ['Microsoft Teams',
                                           'Remote Support Tools']},
 'motivation': 'Financial gain',
 'ransomware': {'data_encryption': True, 'ransomware_strain': 'Chaos'},
 'references': [{'source': 'Sophos'}],
 'threat_actor': 'STAC4749',
 'title': 'Sophos Uncovers Microsoft Teams Vishing Campaign Deploying Chaos '
          'Ransomware',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.