Attackers impersonate IT support staff, use remote access tools, and move quickly from initial contact to ransomware deployment.
Key Takeaways:
Cybercriminals are exploiting Microsoft Teams voice phishing (vishing) campaigns to infiltrate corporate networks and deploy Chaos ransomware. Security researchers warn that the campaign targeted dozens of organizations between February and June 2026.
According to a new report from Sophos, this campaign (tracked as STAC474) focused mainly on organizations in the United States and Canada. It affected multiple industries including services, manufacturing, energy, construction, and legal firms.
The attack began with a voice phishing (vishing) campaign through Microsoft Teams. The attackers posed as legitimate IT support personnel and contacted employees through Teams chats and calls, who claimed they needed to resolve a technical issue or security problem. They created a sense of urgency and appeared trustworthy to persuade victims to start remote support sessions and grant access to their computers.
Once access was obtained, the threat actors used legitimate remote administration tools such as Microsoft Quick Assist and RemSupp to control the victim’s device. They then executed PowerShell commands to download and install custom malware that allowed them to maintain persistent access, collect information about the environment, and communicate with attacker-controlled servers.
Lastly, the attackers expanded their access across the network, deployed additional remote-access utilities, and in some cases exfiltrated data before deploying Chaos ransomware. This operation was designed to move quickly from initial contact to full compromise.
“At least three STAC4749 compromises led to Chaos ransomware deployment. In these incidents, the ransomware was deployed shortly after the attackers expanded access across multiple systems and, in at least one instance, likely exfiltrated data,” explained Sophos threat intelligence analyst Morgan Demboski.
Organizations can reduce the risk of this type of attack by strengthening both their technical defenses and employee awareness. Moreover, security teams should closely monitor unusual external communications, investigate unexpected support requests, and use endpoint detection technologies to identify suspicious PowerShell activity, unauthorized remote-control software, or other indicators of compromise. They should ensure regular audits of startup programs and registry settings can also help discover malicious persistence mechanisms.
Organizations should also prepare employees to recognize social engineering tactics. Staff should be trained to verify the identity of anyone claiming to be from IT support and to be cautious about granting remote access or downloading software at the request of an unknown caller. Organizations can further reduce their exposure by restricting the use of unauthorized applications and enforcing application-control policies.