Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft Teams vishing attacks lead to Chaos ransomware attacks

    July 31, 2026

    ShinyHunters claims Brinks Home breach, threatens to leak stolen data

    July 31, 2026

    Google says AI helped Chrome fix 1,072 security bugs in two releases

    July 31, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Microsoft Teams vishing attacks lead to Chaos ransomware attacks
    News

    Microsoft Teams vishing attacks lead to Chaos ransomware attacks

    adminBy adminJuly 31, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Microsoft Teams

    Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

    Sophos tracks the campaign as STAC4749 and says it targeted dozens of organizations between February and June 2026.

    At least three of these intrusions led to the deployment of Chaos ransomware, with one attack going from initial access to encrypting files in less than 17 hours.

    image

    Sophos says about 95% of the attacks targeted organizations in Canada (50%) and the United States (45%).

    The threat actors targeted organizations across numerous sectors, with services, manufacturing, energy, and construction and engineering experiencing the largest number of attacks.

    Microsoft Teams calls impersonate IT support

    The attacks begin with external Microsoft Teams accounts impersonating IT helpdesk or support personnel in Teams chats and voice calls to targeted employees.

    Calls observed by Sophos lasted between 90 seconds and more than 20 minutes, although most were completed in approximately two to two-and-a-half minutes.

    In past Microsoft Teams social engineering attacks, threat actors would create their own tenants on Microsoft’s onmicrosoft.com domain to initiate communication.

    The STAC4749 campaign diverges from past campaigns by creating IT-themed domains under the “.top” top-level domain. Examples of these domains shared by Sophos are sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top.

    The attackers paired these domains with fake IT support people using the names Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell, who appear to use specific domains tied to those aliases.

    The goal of the calls was to convince employees to launch a remote support session using Microsoft Quick Assist or install another remote monitoring and management tool.

    Sophos says the attackers initially preferred Quick Assist and used the cloud-based RemSupp remote management tool when Quick Assist was unavailable or blocked.

    However, the threat actors later began primarily using RemSupp beginning in April, potentially because it was less likely to be included in corporate application blocklists.

    After gaining remote access to employees’ devices, the attackers used PowerShell to ultimately download a backdoor into the compromised user’s %AppData% folder.

    The malware profiled the system, established persistence, and provided continued remote access to the attackers.

    To make the persistence mechanisms appear legitimate, malicious registry entries were disguised as Realtek and Windows audio components, using names such as “Realtek HD Audio,” “Realtek Audio UHD,” and “WinAudio life2.”

    In incidents that later led to Chaos ransomware deployment, the attackers also installed remote access software such as DWAgent or AnyDesk for backup access to systems on the network. They also attempted to enable Remote Desktop Protocol on compromised devices to move laterally between systems.

    The Sophos report says the attackers continually modified the attack chain between February and May, changing malware filenames, persistence mechanisms, and deployment methods to avoid detection.

    STAC4749's evolution of attack techniques
    STAC4749’s evolution of attack techniques
    Source: Sophos

    Linked to Chaos Ransomware

    At least three STAC4749 compromises ultimately led to Chaos ransomware attacks, with at least one case where the attackers likely stole data before deploying the ransomware.

    Sophos says that when the ransomware was deployed, it encrypted files simultaneously across compromised devices, with ransom notes named “readme.chaos.txt” created on affected systems.

    Chaos ransom notes seen by BleepingComputer all show the same text claiming to have stolen data and warning that it would be leaked if a ransom is not paid.

    Example of Chaos Ransomware notes
    Example of Chaos Ransomware notes
    Source: BleepingComputer

    In one incident seen by Sophos, less than 17 hours passed between the initial Microsoft Teams contact and the deployment of ransomware.

    “Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates,” Sophos said.

    Sophos says the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal ransomware gangs. These ransomware operations were also spinoffs from the notorious Conti cybercrime syndicate.

    Ransomware gangs and other threat actors have increasingly used Microsoft Teams to impersonate corporate IT support employees and convince targets to grant remote access to their devices.

    In October 2024, Black Basta ransomware affiliates were observed flooding employees’ inboxes with unsolicited emails before contacting them through Microsoft Teams as external users.

    Microsoft Teams was also used in more recent attacks attributed to the Iranian state-sponsored MuddyWater hacking group, where the attackers allegedly used Chaos ransomware as a decoy to disguise a cyberespionage operation.

    Sophos says it found no evidence connecting the new STAC4749 campaign to MuddyWater.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleShinyHunters claims Brinks Home breach, threatens to leak stolen data
    admin
    • Website

    Related Posts

    News

    ShinyHunters claims Brinks Home breach, threatens to leak stolen data

    July 31, 2026
    News

    Google says AI helped Chrome fix 1,072 security bugs in two releases

    July 31, 2026
    News

    South Korea fines telco giant KT $39 million for customer data breach

    July 31, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Microsoft Teams vishing attacks lead to Chaos ransomware attacks

    July 31, 2026

    ShinyHunters claims Brinks Home breach, threatens to leak stolen data

    July 31, 2026

    Google says AI helped Chrome fix 1,072 security bugs in two releases

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.