Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
AI Analysis
Technical Summary
The STAC4749 campaign involves threat actors impersonating IT support personnel in Microsoft Teams calls to socially engineer employees into granting remote access. The attackers use external Teams accounts with IT-themed domains under the ".top" TLD and fake personas. They initially favored Microsoft Quick Assist but shifted to RemSupp for remote management. Once access is gained, PowerShell scripts download backdoors that establish persistence via disguised registry entries mimicking audio drivers. Additional remote access tools like DWAgent or AnyDesk are installed for backup access, and attackers attempt to enable RDP for lateral movement. The campaign evolved its techniques to evade detection between February and May 2026. At least three incidents resulted in Chaos ransomware deployment, with one case encrypting files within 17 hours of initial access. The Chaos ransomware-as-a-service group is linked to former BlackSuit and Royal ransomware gangs, themselves spinoffs of Conti. The campaign primarily targeted organizations in Canada and the US across sectors including services, manufacturing, energy, and construction.
Potential Impact
Successful attacks result in unauthorized remote access to corporate devices, enabling attackers to deploy backdoors and establish persistence. This access facilitates lateral movement within networks and the deployment of Chaos ransomware, which encrypts files and threatens data leakage. At least three organizations suffered ransomware attacks, with one incident involving rapid encryption within 17 hours and likely data theft prior to encryption. The campaign disrupts business operations and exposes sensitive data to extortion risks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should be aware of this social engineering threat vector via Microsoft Teams and educate employees to verify IT support requests independently. Blocking or monitoring the use of unauthorized remote support tools like RemSupp may reduce risk. Implementing strict application allowlisting and restricting remote access tools can help prevent unauthorized sessions. Since this is a social engineering attack leveraging legitimate collaboration tools, user training and verification processes are critical.
Affected Countries
Canada, United States
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Description
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The STAC4749 campaign involves threat actors impersonating IT support personnel in Microsoft Teams calls to socially engineer employees into granting remote access. The attackers use external Teams accounts with IT-themed domains under the ".top" TLD and fake personas. They initially favored Microsoft Quick Assist but shifted to RemSupp for remote management. Once access is gained, PowerShell scripts download backdoors that establish persistence via disguised registry entries mimicking audio drivers. Additional remote access tools like DWAgent or AnyDesk are installed for backup access, and attackers attempt to enable RDP for lateral movement. The campaign evolved its techniques to evade detection between February and May 2026. At least three incidents resulted in Chaos ransomware deployment, with one case encrypting files within 17 hours of initial access. The Chaos ransomware-as-a-service group is linked to former BlackSuit and Royal ransomware gangs, themselves spinoffs of Conti. The campaign primarily targeted organizations in Canada and the US across sectors including services, manufacturing, energy, and construction.
Potential Impact
Successful attacks result in unauthorized remote access to corporate devices, enabling attackers to deploy backdoors and establish persistence. This access facilitates lateral movement within networks and the deployment of Chaos ransomware, which encrypts files and threatens data leakage. At least three organizations suffered ransomware attacks, with one incident involving rapid encryption within 17 hours and likely data theft prior to encryption. The campaign disrupts business operations and exposes sensitive data to extortion risks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should be aware of this social engineering threat vector via Microsoft Teams and educate employees to verify IT support requests independently. Blocking or monitoring the use of unauthorized remote support tools like RemSupp may reduce risk. Implementing strict application allowlisting and restricting remote access tools can help prevent unauthorized sessions. Since this is a social engineering attack leveraging legitimate collaboration tools, user training and verification processes are critical.
Affected Countries
Threat ID: 6a6b884a9c2644c7f86a587b
Added to database: 07/30/2026, 17:22:18 UTC
Last enriched: 07/30/2026, 17:22:42 UTC
Last updated: 07/31/2026, 01:59:30 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.