Threat Actors Use Microsoft Teams Calls to Deliver Chaos Ransomware, Compromise Dozens of Organizations in North America
A sophisticated cyber threat campaign has been unfolding in North America, with threat actors impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy the highly destructive Chaos ransomware. The attacks, tracked by Sophos as STAC4749, have targeted dozens of organizations across various sectors between February and June 2026, with at least three intrusions resulting in the deployment of ransomware.
The attackers’ modus operandi is to create external Microsoft Teams accounts that impersonate IT helpdesk or support personnel. They then use these accounts to initiate voice calls or chats with targeted employees, convincing them to launch a remote support session using Microsoft Quick Assist or install another remote monitoring and management tool. In most cases, the calls are brief, lasting between 90 seconds and two-and-a-half minutes. However, in some instances, they can last up to 20 minutes.
The threat actors have diversified their tactics by creating IT-themed domains under the “.top” top-level domain, rather than using Microsoft’s onmicrosoft.com domain as seen in previous campaigns. These domains are paired with fake IT support names and used to deceive employees into granting remote access to their devices. Once inside, the attackers use PowerShell to download a backdoor, which profiles the system, establishes persistence, and provides continued remote access.
In incidents that led to Chaos ransomware deployment, the attackers installed additional malware, such as DWAgent or AnyDesk, for backup access to systems on the network. They also attempted to enable Remote Desktop Protocol on compromised devices to move laterally between systems. The attackers continually modified their attack chain between February and May, changing malware filenames, persistence mechanisms, and deployment methods to evade detection.
Chaos ransomware has been linked to at least three STAC4749 compromises, with one case involving a rapid deployment time of less than 17 hours from initial contact to encryption. In this incident, the attackers likely stole data before deploying the ransomware. The Chaos ransom notes seen by BleepingComputer all contain the same text claiming to have stolen data and threatening to leak it if a ransom is not paid.
The financial motivation behind these attacks is clear, given the short interval between initial access and encryption. Sophos assesses with high confidence that STAC4749 was a financially motivated operation either directly deploying ransomware or coordinating with affiliates. The Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal ransomware gangs.
As this threat campaign continues to evolve, it’s essential for organizations to remain vigilant and take proactive measures to prevent such attacks. Employees should be educated on the risks of remote support sessions initiated through unsolicited Microsoft Teams calls or emails. Organizations should also review their security protocols, including application blocklists and intrusion detection systems, to ensure they can detect and respond quickly to similar threats.
In light of this campaign, it’s crucial for organizations to prioritize employee education, implement robust security measures, and maintain regular system updates to prevent remote exploitation by threat actors.
Source: Bleeping Computer — 2026-07-30