Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Incidents

Recent reports indicate a surge in vishing attacks leveraging Microsoft Teams to deploy Chaos ransomware, primarily targeting North American organizations. This sophisticated campaign, tracked by Sophos as STAC4749, has raised significant concerns among cybersecurity professionals, particularly within Security Operations Centers (SOCs) and IT security teams.

Technical Analysis

The STAC4749 campaign marks a notable evolution in the tactics employed by threat actors. Instead of utilizing traditional phishing methods, attackers are now impersonating IT support personnel during Microsoft Teams calls. This approach allows them to gain remote access to corporate devices, facilitating the deployment of ransomware.

Between February and June 2026, the campaign targeted dozens of organizations, with a staggering 95% of the attacks focused on entities in Canada (50%) and the United States (45%). The sectors most affected include services, manufacturing, energy, and construction.

Affected Systems

The primary systems affected by this campaign are those utilizing Microsoft Teams for internal communications. Given the reliance on remote collaboration tools in modern enterprises, the potential for widespread impact is significant. Organizations using Microsoft 365 are particularly vulnerable, as the attackers exploit the platform's trust and familiarity.

Attack Method / Threat Activity

The attack methodology begins with external Microsoft Teams accounts impersonating IT helpdesk staff. The attackers initiate communication through Teams chats and voice calls, often lasting between 90 seconds and over 20 minutes. However, most interactions are completed within two to two-and-a-half minutes, which is sufficient for the attackers to establish trust and manipulate the target.

Unlike previous campaigns that created their own tenants on the onmicrosoft.com domain, the STAC4749 campaign has adopted a new strategy by registering IT-themed domains under the ".top" top-level domain. Examples include:

  • sequrityupdate.top
  • scan-security.top
  • system-connect.top
  • corp-connect.top
  • supportsoft.top

    📬 Stay ahead of the threat

    Get the latest SOC guides, threat intel, and detection engineering — straight to your inbox.

These domains are paired with fictitious IT support personas, such as Anthony Brooks and Dylan Harper, enhancing the credibility of their communications.

Detection Opportunities

Organizations can enhance their detection capabilities by monitoring for unusual Teams activity. Key indicators include:

  • Unrecognized external accounts initiating calls or chats.
  • Frequent calls from new or suspicious domains.
  • Unusual patterns of communication, such as rapid escalation to sensitive topics.

Employing a Security Information and Event Management (SIEM) system can help correlate these activities with other security events, providing a more comprehensive view of potential threats.

Mitigation Recommendations

To protect against these vishing attacks, organizations should consider the following mitigation strategies:

  • Employee Training: Conduct regular training sessions to educate employees about social engineering tactics, particularly those involving remote communication tools.
  • Multi-Factor Authentication (MFA): Implement MFA for all accounts, especially those with administrative access, to add an additional layer of security.
  • Domain Whitelisting: Maintain a list of approved domains for communication and regularly review external communications for anomalies.
  • Incident Response Planning: Develop and regularly update an incident response plan that includes protocols for handling suspicious communications.

Business Impact

The implications of these vishing attacks extend beyond immediate financial losses. The deployment of Chaos ransomware can lead to significant operational disruptions, data breaches, and reputational damage. Organizations may face regulatory scrutiny and potential legal ramifications, particularly if sensitive customer data is compromised. The rapidity of the attacks—some leading to file encryption within 17 hours—highlights the urgent need for robust security measures.

Final Summary

The STAC4749 campaign underscores the evolving threat landscape where traditional communication platforms are exploited for malicious purposes. By understanding the tactics employed by these threat actors and implementing proactive measures, organizations can better protect themselves against the risks associated with vishing attacks and ransomware deployment. Continuous vigilance, employee education, and effective incident response strategies are essential in mitigating these threats.