Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Best Dyson Vacuums (2026): V15 Detect, Gen5Detect, PencilVac

    July 31, 2026

    Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    July 31, 2026

    Zcash fixed the flaw that nearly halved ZEC, and $926 million in leverage now tests the rebound

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Best Dyson Vacuums (2026): V15 Detect, Gen5Detect, PencilVac
    • Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
    • Zcash fixed the flaw that nearly halved ZEC, and $926 million in leverage now tests the rebound
    • Floating wind turbine that will power UK gas platform ready for tow to offshore site
    • California Fails to Pass Teacher Misconduct Database Bill — ProPublica
    • A Surrogacy Scandal Reveals Germany Is Much More Socially Conservative Than You Think
    • What Tennessee school board’s 2025 policy change means for Pride flag displays
    • BP puts North Sea oil and gas business up for sale | BP
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, July 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Teams vishing attacks lead to Chaos ransomware attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 31, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

    Sophos tracks the campaign as STAC4749 and says it targeted dozens of organizations between February and June 2026.

    At least three of these intrusions led to the deployment of Chaos ransomware, with one attack going from initial access to encrypting files in less than 17 hours.

    image

    Sophos says about 95% of the attacks targeted organizations in Canada (50%) and the United States (45%).

    The threat actors targeted organizations across numerous sectors, with services, manufacturing, energy, and construction and engineering experiencing the largest number of attacks.

    Microsoft Teams calls impersonate IT support

    The attacks begin with external Microsoft Teams accounts impersonating IT helpdesk or support personnel in Teams chats and voice calls to targeted employees.

    Calls observed by Sophos lasted between 90 seconds and more than 20 minutes, although most were completed in approximately two to two-and-a-half minutes.

    In past Microsoft Teams social engineering attacks, threat actors would create their own tenants on Microsoft’s onmicrosoft.com domain to initiate communication.

    The STAC4749 campaign diverges from past campaigns by creating IT-themed domains under the “.top” top-level domain. Examples of these domains shared by Sophos are sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top.

    The attackers paired these domains with fake IT support people using the names Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell, who appear to use specific domains tied to those aliases.

    The goal of the calls was to convince employees to launch a remote support session using Microsoft Quick Assist or install another remote monitoring and management tool.

    Sophos says the attackers initially preferred Quick Assist and used the cloud-based RemSupp remote management tool when Quick Assist was unavailable or blocked.

    However, the threat actors later began primarily using RemSupp beginning in April, potentially because it was less likely to be included in corporate application blocklists.

    After gaining remote access to employees’ devices, the attackers used PowerShell to ultimately download a backdoor into the compromised user’s %AppData% folder.

    The malware profiled the system, established persistence, and provided continued remote access to the attackers.

    To make the persistence mechanisms appear legitimate, malicious registry entries were disguised as Realtek and Windows audio components, using names such as “Realtek HD Audio,” “Realtek Audio UHD,” and “WinAudio life2.”

    In incidents that later led to Chaos ransomware deployment, the attackers also installed remote access software such as DWAgent or AnyDesk for backup access to systems on the network. They also attempted to enable Remote Desktop Protocol on compromised devices to move laterally between systems.

    The Sophos report says the attackers continually modified the attack chain between February and May, changing malware filenames, persistence mechanisms, and deployment methods to avoid detection.

    STAC4749's evolution of attack techniques
    STAC4749’s evolution of attack techniques
    Source: Sophos

    Linked to Chaos Ransomware

    At least three STAC4749 compromises ultimately led to Chaos ransomware attacks, with at least one case where the attackers likely stole data before deploying the ransomware.

    Sophos says that when the ransomware was deployed, it encrypted files simultaneously across compromised devices, with ransom notes named “readme.chaos.txt” created on affected systems.

    Chaos ransom notes seen by BleepingComputer all show the same text claiming to have stolen data and warning that it would be leaked if a ransom is not paid.

    Example of Chaos Ransomware notes
    Example of Chaos Ransomware notes
    Source: BleepingComputer

    In one incident seen by Sophos, less than 17 hours passed between the initial Microsoft Teams contact and the deployment of ransomware.

    “Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates,” Sophos said.

    Sophos says the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal ransomware gangs. These ransomware operations were also spinoffs from the notorious Conti cybercrime syndicate.

    Ransomware gangs and other threat actors have increasingly used Microsoft Teams to impersonate corporate IT support employees and convince targets to grant remote access to their devices.

    In October 2024, Black Basta ransomware affiliates were observed flooding employees’ inboxes with unsolicited emails before contacting them through Microsoft Teams as external users.

    Microsoft Teams was also used in more recent attacks attributed to the Iranian state-sponsored MuddyWater hacking group, where the attackers allegedly used Chaos ransomware as a decoy to disguise a cyberespionage operation.

    Sophos says it found no evidence connecting the new STAC4749 campaign to MuddyWater.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks chaos lead Microsoft ransomware Teams vishing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations

    Critical Flaw Led to Azure Cosmos DB Pwnage

    Sánchez sends armed forces to Ceuta amid migration chaos – POLITICO

    Google says AI helped Chrome fix 1,072 security bugs in two releases

    JetBrains warns of critical TeamCity remote code execution flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Best Dyson Vacuums (2026): V15 Detect, Gen5Detect, PencilVac

    July 31, 2026

    Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    July 31, 2026

    Zcash fixed the flaw that nearly halved ZEC, and $926 million in leverage now tests the rebound

    July 31, 2026

    Floating wind turbine that will power UK gas platform ready for tow to offshore site

    July 31, 2026
    Latest Posts

    Advancing the next era of national science

    July 22, 2026

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026

    Most bus fares in England to be capped at £2 from January

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Best Dyson Vacuums (2026): V15 Detect, Gen5Detect, PencilVac

    July 31, 2026

    Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    July 31, 2026

    Zcash fixed the flaw that nearly halved ZEC, and $926 million in leverage now tests the rebound

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.