Vishing via Microsoft Teams is increasingly being used as a pathway into corporate networks. In a recent campaign tracked by Sophos, threat actors impersonated IT support personnel during Teams chats and voice calls, convincing employees to grant remote access. Once inside, the attackers moved quickly—profiling systems, establishing persistence, and in several cases deploying Chaos ransomware.
Between February and June 2026, the operation targeted dozens of organizations across North America. According to Sophos, at least three intrusions ultimately led to Chaos ransomware activity, with one incident showing a remarkably short window between the first Teams contact and file encryption.
What the Sophos report describes
Sophos tracks this campaign as STAC4749. The activity focused largely on organizations in Canada (about 50%) and the United States (about 45%). The remaining cases were spread across other environments in North America.
While no single industry dominated, Sophos reports that the highest number of attacks occurred in services, manufacturing, energy, and construction and engineering.
How vishing via Microsoft Teams starts
The attack begins externally. Threat actors use outside Microsoft Teams accounts to impersonate IT helpdesk or support staff. They then contact employees through Teams chats and voice calls, aiming to create urgency and trust in a way employees associate with real internal support.
The call durations Sophos observed varied widely, ranging from roughly 90 seconds to more than 20 minutes. However, most calls ended after about two to two-and-a-half minutes, suggesting a playbook designed to reach the remote-access step quickly.
The infrastructure and impersonation details
Rather than relying on earlier approaches where attackers set up their own tenants on Microsoft’s onmicrosoft.com domain, this campaign took a different route. Sophos says the attackers registered IT-themed domains under the .top top-level domain.
Examples Sophos shared include: sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top.
These domains were paired with fake IT support identities, including names such as Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell. Sophos indicates that the aliases were associated with domains linked to those personas.
Remote access: the critical moment
The objective of the Teams interaction was straightforward: get employees to launch a remote support session or install another tool that enables remote monitoring and management.
Targets were asked to use Microsoft Quick Assist, or—if that path was unavailable—install an alternative remote management capability. Sophos reports that the attackers initially favored Quick Assist, and when Quick Assist could not be used, they relied on a cloud-based tool named RemSupp.
Later in the campaign, starting in April, Sophos observed a shift toward primarily using RemSupp. One possible reason given in the report is that RemSupp may have been less likely to appear in corporate application blocklists.
From access to malware: what happened after the call
Once remote access was obtained, attackers used PowerShell to ultimately place a backdoor into the compromised user’s %AppData% folder. After installation, the malware was used to profile the system, establish persistence, and keep access available for continued activity.
To make persistence look more legitimate, the attackers disguised malicious registry activity as components tied to audio software. Sophos reports registry entries were disguised with names resembling Realtek and Windows audio items, including labels such as “Realtek HD Audio”, “Realtek Audio UHD”, and “WinAudio life2”.
Additional remote tools and lateral movement attempts
In incidents that later led to Chaos ransomware, the attackers also installed remote access software including DWAgent or AnyDesk to maintain backup-style access. They also attempted to enable Remote Desktop Protocol (RDP) on compromised devices, with the goal of moving laterally across the network.
Changing tactics to avoid detection
Another notable element is adaptation. Sophos says the attackers modified parts of the chain between February and May. Changes included altering malware filenames, updating persistence mechanisms, and shifting deployment methods. This behavior is consistent with a campaign trying to reduce the chance that defenders can detect repeated, static patterns.
Link to Chaos ransomware
At least three STAC4749 intrusions resulted in Chaos ransomware activity. In at least one case, Sophos indicates the attackers likely stole data before deploying ransomware—an approach that can increase pressure during extortion.
When ransomware was deployed, files were encrypted simultaneously across compromised devices. A ransom note named readme.chaos.txt appeared on affected systems.
Across the notes BleepingComputer reviewed, the wording was consistent: it stated that data had been taken and warned that it would be leaked if a ransom was not paid.
A fast timeline
One incident observed by Sophos highlights how quickly the chain could complete. In less than 17 hours, the operation progressed from the initial Microsoft Teams contact to ransomware deployment and encryption.
Given that short interval, Sophos analysts assessed with high confidence that STAC4749 was either financially motivated and directly deployed ransomware, or worked in coordination with affiliate actors.
Why Teams impersonation is becoming common
This activity fits a broader pattern: threat groups increasingly use Microsoft Teams to impersonate corporate IT support staff and obtain remote access. The report cites additional examples from earlier incidents where Teams helped attackers reach employees, whether through unsolicited messaging, external user contact patterns, or using ransomware as part of a distraction strategy.
Sophos says it found no evidence linking STAC4749 to the MuddyWater state-sponsored hacking group, which has been associated with other Microsoft Teams-related activity. Still, the presence of recurring techniques underscores that defenders should treat Teams impersonation as a high-risk scenario, not a one-off phishing variation.
Defenders: focus on each layer, not just one
The practical takeaway is that stopping these attacks requires more than a single detection point. Sophos notes that security teams log around 54% of successful attacks and alert on only about 14%. The remainder can move through environments without being noticed.
To improve coverage, organizations can validate whether their SIEM and EDR rules actually catch the behavior sequences used by real attackers. Attack and breach simulation helps teams identify blind spots before adversaries do—especially when the threat chain includes social engineering, remote access, scripting, persistence via registry tricks, and rapid escalation to encryption.
Conclusion
Vishing via Microsoft Teams can turn a casual helpdesk interaction into a full ransomware incident. The STAC4749 campaign shows a clear chain: impersonation in Teams chats and calls, remote-access approval through tools like Quick Assist or RemSupp, backdoor placement using PowerShell, persistence disguised as legitimate registry entries, and—within a matter of hours in at least one case—Chaos ransomware deployment.
For security teams, the message is urgent: verify defenses across every stage, train employees to recognize support impersonation attempts, and validate monitoring so attackers can’t slip past without being detected.
