Chaos ransomware through Microsoft Teams encrypted a network in just 17 hours
- Evelyn Carter

- Aug 3
- 4 min read
A Microsoft Teams call lasting only a few minutes can be enough for attackers to bypass multiple layers of security if an employee believes the caller is a legitimate member of the internal IT team.
Instead of delivering malicious attachments, directing victims to phishing websites, or exploiting software vulnerabilities, the threat actor tracked as STAC4749 relies on voice phishing (vishing) to persuade users to initiate a remote support session themselves.
What makes this campaign particularly concerning is not only the deployment of Chaos ransomware, but also the speed of the attack chain. Once remote access is granted, attackers can install backdoors, establish persistence, move laterally across the network, and steal sensitive data before encrypting systems.
What happened in the STAC4749 campaign?
STAC4749 is the name Sophos assigned to a financially motivated threat campaign targeting dozens of organizations across North America between February and June 2026.

Attackers contacted employees through Microsoft Teams chats or voice calls while impersonating internal helpdesk or IT support personnel. Display names, domains, and conversation scripts were carefully crafted to make the interaction appear to be a routine technical support request.
During these conversations, victims were persuaded to:
Launch Microsoft Quick Assist.
Enter or share a remote support session code.
Approve remote viewing or control requests.
Install an alternative remote administration tool if Quick Assist was unavailable.
Believe that PowerShell commands or software downloads were legitimate parts of the support process.
What makes this campaign particularly dangerous?
Sophos observed that the campaign primarily targeted organizations in Canada and the United States. However, the attack technique can be applied to virtually any organization that uses Microsoft Teams and allows communication with external accounts.
Findings | Details |
Observed period | February–June 2026 |
Organizations targeted | Dozens |
Canadian victims | 50% |
U.S. victims | 44% |
Combined | Nearly 95% |
Services sector | 20% |
Manufacturing | 17% |
Energy | 12% |
Construction & Engineering | 12% |
Incidents leading to Chaos ransomware | At least three |
Fastest time to encryption | Less than 17 hours |
The most alarming finding is the operational speed. In at least one incident, attackers progressed from the initial Microsoft Teams contact to full ransomware deployment in under 17 hours, leaving organizations with very little time to detect and contain the intrusion.
How does a Microsoft Teams call turn into a ransomware attack?
Once the victim approves remote access, attackers combine legitimate administration tools with custom malware to establish persistent control over the compromised system.
1. Impersonating internal IT staff
The attack begins with a Microsoft Teams call or message from an external account disguised as corporate IT support. The objective is to convince employees that the request is part of a legitimate troubleshooting process.
This is not the first time Microsoft Teams has been abused in social engineering campaigns. Previous campaigns, including EtherRAT, also combined fake IT support calls with legitimate remote administration software to compromise enterprise environments.
2. Abusing remote assistance tools
Microsoft Quick Assist is typically the first tool used to gain remote access. If Quick Assist is unavailable or blocked by organizational policies, attackers may switch to RemSupp or other remote management applications.
3. Deploying backdoors and establishing persistence
After gaining control of the endpoint, attackers execute PowerShell commands to download malicious components into writable user directories such as %AppData%.
The malware collects system information, identifies installed security products, and creates persistence mechanisms through the Windows Registry to survive system reboots.
4. Creating multiple access channels
In incidents that resulted in Chaos ransomware deployment, attackers also installed DWAgent or AnyDesk. They attempted to enable Remote Desktop Protocol (RDP) to facilitate lateral movement across the network.
Using multiple remote access tools ensures continued access even if the original Quick Assist session is terminated.
5. Encrypting the environment
Once the attackers have established sufficient control, Chaos ransomware is deployed across multiple endpoints simultaneously.
The malware creates ransom notes such as readme.chaos.txt after encrypting files. In one documented case, the entire attack chain from the first Microsoft Teams conversation to ransomware execution—was completed in less than 17 hours.
Which organizations are most at risk?
Organizations may face elevated risk if they:
Frequently support remote employees.
Conduct IT support sessions through Microsoft Teams.
Allow external Teams accounts to initiate chats or calls.
Do not control the use of Quick Assist, AnyDesk, DWAgent, or other remote management tools.
Grant excessive local administrator privileges.
Lack visibility into PowerShell, Registry, RDP, or endpoint activities.
Operate without a dedicated cybersecurity team or continuous security monitoring.
What should organizations do within the first 24 hours?
Organizations should immediately review remote support procedures, audit approved remote administration tools, and improve detection capabilities. Given that STAC4749 can move from initial access to ransomware deployment in under 17 hours, relying solely on next-day security reviews may not provide enough response time.
If compromise is suspected, affected devices should be isolated while preserving forensic evidence. Organizations should avoid deleting logs or shutting down systems before incident responders have collected the necessary data.
Expert insight from IPSIP Vietnam
The campaign demonstrates that trusted collaboration platforms can become effective attack vectors when organizations rely solely on user trust instead of identity verification.
The root issue is not a Microsoft Teams software vulnerability but weaknesses in remote support workflows and identity validation. Once attackers obtain remote control through social engineering, legitimate administrative tools can be abused to establish persistence, move laterally, and eventually deploy ransomware.
Organizations should strengthen remote support verification procedures, implement least-privilege access, monitor endpoint behavior, control remote administration tools, and expand cybersecurity awareness training beyond traditional email phishing scenarios.

Employees should learn how to verify Microsoft Teams calls, remote assistance requests, and screen-sharing invitations before granting access to corporate devices.
References









Comments