Between February and June 2026, threat actors tracked as STAC4749 utilized vishing via Microsoft Teams to impersonate IT support, tricking employees into installing remote management tools like Microsoft Quick Assist and RemSupp, ultimately deploying the Chaos ransomware across North American corporate networks.
Anatomy of a Teams Helpdesk Impersonation
Modern enterprise collaboration platforms have become prime vectors for social engineering. According to threat intelligence data released by Sophos, the STAC4749 campaign systematically targeted organizations across Canada and the United States between February and June 2026. Roughly 95 percent of these attacks hit North American enterprises, heavily impacting the services, manufacturing, energy, engineering, and construction sectors.
The operational playbook is straightforward yet deeply effective. Attackers leverage compromised external Microsoft Teams accounts to initiate chats and voice calls with corporate employees. They pose as internal IT helpdesk personnel. While observed call durations varied widely—ranging from 90 seconds to over 20 minutes—the bulk of the social engineering interactions wrapped up in roughly two to two and a half minutes. That is all the time an adversary needs to build artificial urgency.
Unlike previous campaigns that relied entirely on free public infrastructure, STAC4749 registered dedicated, IT-themed domains under the .top TLD. Domains like sequrityupdate.top and system-connect.top added a veneer of corporate legitimacy, paired with fabricated names for the supposed support agents. The ultimate objective of these calls remained consistent: coerce employees into launching a remote maintenance session via Microsoft Quick Assist or installing alternative remote administration software.
From Remote Access to Persistent Backdoors
Once an employee granted remote desktop access, the technical execution shifted rapidly toward automation. Attackers deployed PowerShell scripts to fetch and execute a persistent backdoor directly inside the user’s AppData directory. This payload evaluated the infected machine, establishing a reliable, long-term remote foothold.
To evade standard endpoint detection and response (EDR) telemetry and manual auditing, the threat actors disguised their persistence mechanisms. Registry modifications were deliberately mislabeled to mimic legitimate components, such as Realtek or Windows audio drivers. In cases that escalated toward full-scale enterprise extortion, operators dropped additional remote-access tools like DWAgent and AnyDesk as secondary fallback access channels, attempting to enable native Remote Desktop Protocol (RDP) functions for lateral movement.
The speed of execution remains a defining technical characteristic of the STAC4749 operation. Sophos confirmed that at least three of the investigated compromises ended in the deployment of the Chaos ransomware. In at least one instance, this followed active data exfiltration. Encryption routines executed files nearly simultaneously across all compromised endpoints, accompanied by explicit ransom notes bearing the filename readme.chaos.txt. In one documented case, the window between the initial Teams chat message and total network encryption was under 17 hours.
Historical Lineage and Ransomware-as-a-Service Roots
The Chaos ransomware group operates under a Ransomware-as-a-Service (RaaS) model. According to Sophos tracking, the collective has been active since February 2025. Technical attribution links the core operators to former members of the BlackSuit and Royal ransomware groups, both of which trace their origins back to the infrastructure and personnel of the now-defunct Conti syndicate.
The exploitation of Microsoft Teams for fraudulent IT support pretexts is part of an evolving threat landscape. In 2024, suspected Black Basta affiliates utilized a remarkably similar methodology, while the actor MuddyWater adopted comparable tactics in separate operations. However, Sophos reported no observable technical overlap or connection between STAC4749 and MuddyWater.
The 30-Second Verdict for Enterprise Security Teams
- Primary Vector: External Microsoft Teams accounts spoofing internal IT helpdesks via voice calls.
- Tooling Shift: Initial reliance on Microsoft Quick Assist, transitioning to RemSupp in April 2026 to evade corporate blocklists.
- Payload & Persistence: PowerShell-deployed backdoors hidden via registry keys mimicking audio drivers, supplemented by DWAgent and AnyDesk.
- Impact: Rapid deployment of Chaos ransomware, with end-to-end compromise windows as short as 17 hours.
Defending against human-operated social engineering inside collaboration apps requires strict identity verification policies. Organizations must enforce strict boundaries around who can initiate inbound Teams communications from outside the corporate tenant, alongside strict application control policies to block unauthorized remote administration binaries.