Cyberattackers are using Microsoft Teams calls to gain access to corporate devices, deploying Chaos ransomware in a campaign targeting North American organizations. The attacks, tracked by cybersecurity firm Sophos as STAC4749, began in February 2026 and have resulted in at least three intrusions leading to the deployment of Chaos ransomware.
The attackers are impersonating IT support staff in Microsoft Teams calls, convincing employees to launch remote support sessions or install monitoring tools on their devices. This is a sophisticated social engineering tactic that relies on the trust between employees and IT personnel. The calls often lasted just a few minutes, but were enough for the attackers to gain remote access to corporate devices.
Once inside, the threat actors used PowerShell to download a backdoor onto compromised user’s devices. This malware profiled the system, established persistence, and provided continued remote access to the attackers. To make their persistence mechanisms appear legitimate, malicious registry entries were disguised as Realtek and Windows audio components.
The attackers also installed remote access software such as DWAgent or AnyDesk for backup access to systems on the network. They attempted to enable Remote Desktop Protocol on compromised devices to move laterally between systems. This shows a high level of sophistication in their tactics, allowing them to maintain control over compromised devices for extended periods.
At least three STAC4749 compromises ultimately led to Chaos ransomware attacks, with one case showing that less than 17 hours passed between the initial Microsoft Teams contact and the deployment of ransomware. Sophos assesses this operation as financially motivated, either directly deploying ransomware or coordinating with affiliates. This campaign diverges from past Microsoft Teams social engineering attacks by creating IT-themed domains under the “.top” top-level domain.
The Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal ransomware gangs. Organizations targeted in this campaign include services, manufacturing, energy, and construction and engineering sectors, with Canada (50%) and the United States (45%) being the primary locations.
The rapid pace at which these attacks unfolded highlights the importance of vigilance in cybersecurity defenses. Employees must be aware of suspicious calls or messages from IT personnel, even if they seem legitimate. Furthermore, organizations should review their security protocols to ensure that remote access tools are properly configured and monitored.
In the face of such sophisticated social engineering tactics, it is crucial for employees to remain cautious when interacting with external parties over Microsoft Teams. This includes verifying the authenticity of IT support personnel before granting them access to corporate devices. Additionally, organizations must stay up-to-date with the latest security patches and updates to prevent exploitation by attackers.
While this campaign may have been driven by financial motives, it serves as a stark reminder that cybersecurity threats are constantly evolving. As such, organizations must remain proactive in their defenses, adopting multiple layers of protection to safeguard against these types of attacks.
Source: Bleeping Computer — 2026-07-30