Sophos researchers have uncovered a Microsoft Teams voice phishing campaign that used fake IT support calls to gain remote access to corporate systems and deploy Chaos ransomware.
Tracked as STAC4749, the campaign targeted dozens of North American organizations between February and June 202620262026.
The attackers impersonated helpdesk staff through Microsoft Teams chats and voice calls, persuading employees to launch remote access tools or install software.
Sophos said the group used a modular malware toolkit after gaining access. The tools enabled system discovery, persistence, command execution, remote access, and lateral movement before ransomware deployment.
In at least three incidents, the attackers deployed Chaos ransomware after expanding across victim networks.
The operation appears financially motivated and focused on speed. In one case, ransomware encryption began less than 171717 hours after the initial compromise.
Teams Vishing Chaos Ransomware
The attackers contacted targets using Microsoft Teams accounts created with IT-themed usernames and domains.
They used names such as AnthonyBrooks, DylanHarper, EthanParker, and EllaBrooks, paired with suspicious domains including sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, and service-help[.]top.

Unlike earlier Teams abuse campaigns that often relied on spoofed onmicrosoft[.]com tenants, STAC4749 used custom .top domains to make fraudulent accounts appear more credible.
The actors posed as internal IT workers and attempted to convince employees that their devices required technical support.
Calls ranged from around 909090 seconds to more than 202020 minutes, although most lasted between two and two-and-a-half minutes.
The objective was to get users to open Microsoft Quick Assist or install an alternative remote monitoring and management tool.
Initially, the group favored Microsoft Quick Assist. However, from April onward, the actors increasingly used RemSupp.
This cloud-based remote support tool may be less likely to appear in application blocklists. In later stages, they also attempted to enable Remote Desktop Protocol by modifying Windows service configurations through msconfig.

Microsoft Teams vishing has become an increasingly common initial access method for ransomware operators. Sophos observed a significant rise in Teams-related vishing cases in January 202620262026, followed by further increases in March and May.
Earlier campaigns linked to Black Basta, 3 AM, and other ransomware activity similarly used Teams calls, email bombing, and remote support tools to compromise organizations.
Nearly 95%95\%95% of observed STAC4749 cases targeted Canadian and US organizations. The campaign affected multiple sectors, including services, manufacturing, energy, construction, engineering, and intellectual property law firms.
After establishing a remote session, STAC4749 operators used PowerShell to download payloads from attacker-controlled servers. The files were commonly placed in user-writable folders such as AppData\Roaming, sophos said.
Early attacks used loaders with changing filename patterns, including sekv<random digits>.exe, helper<random digits>.exe, and 74fs<random digits>.exe.
These loaders profiled compromised devices, checked for security products, created persistence, and contacted command-and-control infrastructure using gRPC.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.