Teams Impersonations Fuel Chaos Ransomware Deployments Across North America

TL;DR Summary
Sophos warns of STAC4749, a vishing campaign in which external Microsoft Teams calls impersonate IT staff to gain remote access, deploying backdoors and culminating in Chaos ransomware across dozens of North American organizations (Canada ~50%, US ~45%). Attackers used fake IT domains under the .top TLD, relied on Quick Assist or RemSupp, then PowerShell to install persistence and remote access tools like DWAgent/AnyDesk, with RDP used for lateral movement. Ransomware encrypts files and may accompany data theft; Chaos-as-a-service is linked to Conti offshoots. The techniques evolved to evade detection; no confirmed link to MuddyWater.
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer
- Chaos in Teams vishing Sophos
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News
- Hackers abuse Microsoft Teams in ransomware campaign through fake IT support Yahoo
- Teams Vishing and Quick Assist Deploy GoGRPC Backdoor SOC Prime
Reading Insights
Total Reads
1
Unique Readers
7
Time Saved
5 min
vs 6 min read
Condensed
91%
1,034 → 94 words
Want the full story? Read the original article
Read on BleepingComputer