Sophos Uncovers Microsoft Teams Vishing Campaign Deploying Chaos Ransomware
Sophos researchers identified a sophisticated voice phishing (vishing) campaign, tracked as STAC4749, targeting North American organizations between February and June 2026. The attackers impersonated IT support staff via Microsoft Teams chats and calls, tricking employees into granting remote access to corporate systems before deploying Chaos ransomware.
Attack Methodology
The threat actors used fake Microsoft Teams accounts with IT-themed usernames (e.g., AnthonyBrooks, DylanHarper) and domains like sequrityupdate[.]top and service-help[.]top to appear legitimate. Unlike previous campaigns that relied on spoofed onmicrosoft[.]com domains, STAC4749 employed custom .top domains to enhance credibility.
Once contact was established, the attackers persuaded victims to:
- Launch Microsoft Quick Assist (early in the campaign)
- Install RemSupp, a cloud-based remote support tool (used increasingly from April onward)
- Enable Remote Desktop Protocol (RDP) by modifying Windows service configurations
Calls typically lasted 2–2.5 minutes, with some extending beyond 20 minutes, to convince employees of an urgent IT issue.
Post-Compromise Activity
After gaining access, the attackers deployed a modular malware toolkit to:
- Conduct system discovery
- Establish persistence
- Execute commands
- Move laterally across networks
- Deploy Chaos ransomware in at least three confirmed incidents
In one case, ransomware encryption began in under 17 hours after the initial compromise, indicating a fast-moving, financially motivated operation.
Targeted Sectors & Impact
Nearly 95% of observed attacks focused on Canadian and U.S. organizations, with victims spanning:
- Services
- Manufacturing
- Energy
- Construction & Engineering
- Intellectual property law firms
Sophos noted a rise in Teams-based vishing since January 2026, with similar tactics previously linked to Black Basta, 3 AM, and other ransomware groups. The campaign highlights the growing use of remote support tools as an initial access vector for ransomware operators.
Source: https://cyberpress.org/teams-vishing-chaos-ransomware/
Microsoft Security Response Center cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security-response-center
"id": "MIC1785399995",
"linkid": "microsoft-security-response-center",
"type": "Ransomware",
"date": "2/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Services',
'Manufacturing',
'Energy',
'Construction & Engineering',
'Intellectual Property Law Firms'],
'location': ['Canada', 'United States'],
'type': 'Organization'}],
'attack_vector': ['Vishing (Voice Phishing)',
'Microsoft Teams',
'Remote Support Tools'],
'data_breach': {'data_encryption': True},
'date_detected': '2026-02-01',
'description': 'Sophos researchers identified a sophisticated voice phishing '
'(vishing) campaign, tracked as STAC4749, targeting North '
'American organizations between February and June 2026. The '
'attackers impersonated IT support staff via Microsoft Teams '
'chats and calls, tricking employees into granting remote '
'access to corporate systems before deploying Chaos '
'ransomware.',
'initial_access_broker': {'entry_point': ['Microsoft Teams',
'Remote Support Tools']},
'motivation': 'Financial gain',
'ransomware': {'data_encryption': True, 'ransomware_strain': 'Chaos'},
'references': [{'source': 'Sophos'}],
'threat_actor': 'STAC4749',
'title': 'Sophos Uncovers Microsoft Teams Vishing Campaign Deploying Chaos '
'Ransomware',
'type': 'Ransomware'}