Recent cybersecurity reports have unveiled a new threat involving brief Microsoft Teams calls, which are being exploited by cybercriminals to initiate ransomware attacks. The attackers disguise themselves as IT support personnel, deceiving employees into granting remote access. This tactic is then used to penetrate networks and deploy the Chaos ransomware, posing a significant threat to organizational security.
Understanding the Threat
The campaign, identified as STAC4749, has primarily targeted organizations in North America between February and June 2026. These attacks demonstrate the rapidity and efficiency of social engineering, with fraudulent calls typically lasting just over two minutes. This approach underscores the vulnerability of organizations that inherently trust collaboration platforms without sufficient scrutiny.
According to Sophos, the attackers employ a combination of Teams voice phishing, bespoke malware, and legitimate remote administration tools, making it challenging to detect their activities. The methods used by the attackers are in constant evolution, complicating efforts to thwart their malicious endeavors.
Methods of Attack
Attackers begin their operations by reaching out through Teams chats and calls, impersonating IT helpdesk personnel. They craft credible personas using familiar employee names and IT-themed cloud domains. Their goal is to gain access via Microsoft Quick Assist or similar remote management applications, mimicking legitimate support interactions.
Once access is granted, the attackers execute commands to gather system information, identify security measures, and establish persistent access. They have been known to enable Remote Desktop Protocol to facilitate lateral movement within the network, magnifying the potential damage.
Rapid Ransomware Deployment
Upon securing network access, the cybercriminals deploy a suite of tools to maintain control and expand their reach. In several incidents, this has culminated in the deployment of Chaos ransomware, which rapidly encrypts endpoints, often within hours of initial access. This swift escalation leaves little opportunity for defenders to respond effectively.
Chaos ransomware has been a component of ransomware-as-a-service operations since early 2025. Its integration with voice phishing and remote management tools exemplifies a growing trend where attackers exploit trusted cloud services to circumvent traditional security measures.
Preventive Measures
Organizations must remain vigilant against unexpected Teams messages and calls, particularly those requesting remote support sessions or software installations. Verifying support requests through established internal channels is crucial to mitigating risks.
Security teams should closely monitor Teams activity, scrutinize unusual command-line use, and restrict unauthorized remote administration tools. Educating employees about these threats and enforcing strict software execution policies can significantly enhance organizational resilience against such attacks.
In conclusion, as cyber threats evolve, it is imperative for organizations to adapt and strengthen their cybersecurity frameworks. By understanding the tactics used in these attacks and implementing robust preventive measures, companies can safeguard their networks from emerging threats.
