Microsoft Teams Under Attack: Fake IT Support Deploying Chaos Ransomware
A new campaign, tracked as **STAC4749** by **Sophos**, is exploiting **Microsoft Teams** to impersonate IT support and gain remote access to corporate devices. Threat actors are deploying **Chaos ransomware** in attacks predominantly targeting North American organizations, with some intrusions escalating from initial access to full encryption in under 17 hours.
Threat actors are leveraging **Microsoft Teams** to execute sophisticated social engineering attacks, posing as IT support staff to infiltrate corporate networks and deploy **Chaos ransomware**. The campaign, dubbed **STAC4749** by **Sophos**, has targeted dozens of organizations, primarily in Canada and the United States, between February and June 2026.

### Impersonation on Microsoft Teams
The attacks commence with external **Microsoft Teams** accounts impersonating IT helpdesk or support personnel. These attackers initiate chats and voice calls with targeted employees, often lasting a few minutes but sometimes extending beyond 20 minutes.
Unlike previous campaigns that relied on **Microsoft's onmicrosoft.com** domain, **STAC4749** utilizes IT-themed domains under the ".top" top-level domain. Examples include sequrityupdate[.]top, scan-security[.]top, and supportsoft[.]top. These domains are paired with fake IT support aliases such as Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell.
### Gaining Remote Access
The primary objective of these calls is to persuade employees to launch a remote support session. Initially, the attackers favored **Microsoft Quick Assist**, but later shifted to the cloud-based **RemSupp** remote management tool, possibly due to its lower likelihood of being blocked by corporate application policies.
Upon gaining remote access, the attackers use **PowerShell** to download a backdoor into the compromised user's %AppData% folder. This malware profiles the system, establishes persistence, and ensures continued remote access. To evade detection, malicious registry entries are disguised as legitimate **Realtek** and **Windows** audio components.
In incidents leading to **Chaos ransomware** deployment, additional remote access software like **DWAgent** or **AnyDesk** is installed for backup access. Attackers also attempt to enable **Remote Desktop Protocol** (RDP) to facilitate lateral movement within the network.
**Sophos** reports that the attack chain was continually modified between February and May, with changes to malware filenames, persistence mechanisms, and deployment methods, indicating an adaptive adversary.

*Source: Sophos*
### The Chaos Ransomware Connection
At least three **STAC4749** compromises culminated in **Chaos ransomware** attacks. In one notable instance, less than 17 hours elapsed between the initial **Microsoft Teams** contact and the deployment of ransomware. **Sophos** assesses with high confidence that **STAC4749** is a financially motivated operation, either directly deploying ransomware or coordinating with affiliates.
When deployed, **Chaos ransomware** encrypts files simultaneously across compromised devices, leaving ransom notes named "readme.chaos.txt." These notes typically claim data exfiltration and threaten public release if the ransom is not paid.

*Source: BleepingComputer*
The **Chaos** ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the **BlackSuit** and **Royal ransomware gangs**, both of which are spin-offs from the notorious **Conti cybercrime syndicate**.
This campaign highlights a growing trend of threat actors using **Microsoft Teams** for social engineering. Previous incidents include **Black Basta** ransomware affiliates posing as IT support on **Microsoft Teams** in October 2024, and the Iranian state-sponsored **MuddyWater** hacking group allegedly using **Chaos ransomware** as a decoy in cyberespionage operations. However, **Sophos** found no evidence linking the current **STAC4749** campaign to **MuddyWater**.