Teams Impersonations Fuel Chaos Ransomware Deployments Across North America

TL;DR
Sophos warns of STAC4749, a vishing campaign in which external Microsoft Teams calls impersonate IT staff to gain remote access, deploying backdoors and culminating in Chaos ransomware across dozens of North American organizations (Canada ~50%, US ~45%). Attackers used fake IT domains under the .top TLD, relied on Quick Assist or RemSupp, then PowerShell to install persistence and remote access tools like DWAgent/AnyDesk, with RDP used for lateral movement. Ransomware encrypts files and may accompany data theft; Chaos-as-a-service is linked to Conti offshoots. The techniques evolved to evade detection; no confirmed link to MuddyWater.
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer
- Chaos in Teams vishing Sophos
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News
- Hackers abuse Microsoft Teams in ransomware campaign through fake IT support Yahoo
- Teams Vishing and Quick Assist Deploy GoGRPC Backdoor SOC Prime
Want the full story? Read the original reporting
Read on BleepingComputer