Microsoft Teams vishing attacks lead to Chaos ransomware attacks
AI Summary
Threat actors are conducting vishing attacks via Microsoft Teams, impersonating IT support staff to trick employees into granting remote access to corporate devices. These intrusions are part of campaign STAC4749, tracked by Sophos, which led to the deployment of Chaos ransomware in at least three organizations. The attackers used fake IT-themed domains and spoofed identities to initiate contact, then deployed remote management tools like RemSupp and PowerShell-based backdoors to establish persistence and move laterally. The campaign targeted primarily North American organizations, with attacks spanning from February to June 2026, and demonstrated rapid progression from initial access to ransomware encryption—sometimes within 17 hours.
AI-extracted · verify before operational use