Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors tracked as STAC4749 used Microsoft Teams calls to impersonate IT support staff and trick employees into granting remote access, leading to attacks on dozens of North American organizations. At least three intrusions resulted in Chaos ransomware deployment, with one case reaching file encryption in under 17 hours. #STAC4749 #MicrosoftTeams #ChaosRansomware

Keypoints

  • STAC4749 targeted dozens of organizations from February to June 2026.
  • Most victims were in Canada and the United States.
  • The attackers used Microsoft Teams calls to impersonate IT support staff.
  • They used Quick Assist, RemSupp, and other tools to gain remote access and persist on devices.
  • At least three compromises led to Chaos ransomware, with possible data theft before encryption.

Read More: https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/