Skip to content
Tech News
← Back to articles

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

read original more articles
Why This Matters

The rise of vishing attacks via Microsoft Teams impersonations highlights a new vector for ransomware deployment, emphasizing the need for enhanced security awareness and verification protocols among organizations. These campaigns demonstrate how threat actors exploit trusted communication platforms to target North American businesses across various sectors, leading to significant operational and financial risks.

Key Takeaways

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

Sophos tracks the campaign as STAC4749 and says it targeted dozens of organizations between February and June 2026.

At least three of these intrusions led to the deployment of Chaos ransomware, with one attack going from initial access to encrypting files in less than 17 hours.

Sophos says about 95% of the attacks targeted organizations in Canada (50%) and the United States (45%).

The threat actors targeted organizations across numerous sectors, with services, manufacturing, energy, and construction and engineering experiencing the largest number of attacks.

Microsoft Teams calls impersonate IT support

The attacks begin with external Microsoft Teams accounts impersonating IT helpdesk or support personnel in Teams chats and voice calls to targeted employees.

Calls observed by Sophos lasted between 90 seconds and more than 20 minutes, although most were completed in approximately two to two-and-a-half minutes.

In past Microsoft Teams social engineering attacks, threat actors would create their own tenants on Microsoft's onmicrosoft.com domain to initiate communication.

The STAC4749 campaign diverges from past campaigns by creating IT-themed domains under the ".top" top-level domain. Examples of these domains shared by Sophos are sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top.

... continue reading