Sophos tracked STAC4749, a Microsoft Teams vishing campaign that impersonated IT support using themed cloud domains and personas to gain access to dozens of North American organizations. The operators used a modular backdoor toolset, remote access utilities, and evolving evasion tactics, with several intrusions ending in Chaos ransomware deployment. #STAC4749 #Chaos #MicrosoftTeams #Sophos #RemSupp #QuickAssist
Keypoints
- STAC4749 used Microsoft Teams vishing to impersonate helpdesk and IT support staff.
- The campaign mainly targeted organizations in Canada and the United States.
- Attackers used .top domains, Quick Assist, and RemSupp to gain remote access.
- Their payload chain included loaders, backdoors, persistence via Run keys, and tunneling tools.
- Some intrusions escalated to Chaos ransomware after lateral movement and data theft.
Read More: https://www.sophos.com/en-us/blog/chaos-in-teams-vishing