top of page
perceptive_background_267k.jpg

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Published:

30 juli 2026 om 17:56:33

Alert date:

30 juli 2026 om 18:04:07

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Ransomware & Malware, Email & Messaging, Identity & Access, Data Breach & Exfiltration

Threat actors are conducting vishing (voice phishing) attacks via Microsoft Teams by impersonating IT support staff to gain remote access to corporate devices. Once access is established, the attackers deploy Chaos ransomware against targeted organizations. The campaign is primarily targeting North American organizations. The attack vector involves social engineering through Microsoft Teams calls, making it particularly dangerous as it abuses a trusted enterprise communication platform. This technique bypasses traditional email-based phishing defenses and exploits user trust in internal IT support channels.

Technical details

Threat actor group STAC4749 (tracked by Sophos) conducted vishing attacks via Microsoft Teams between February and June 2026, targeting North American organizations. Attackers impersonated IT helpdesk/support personnel using external Teams accounts registered under IT-themed '.top' TLD domains (e.g., sequrityupdate[.]top, scan-security[.]top). Fake personas used included Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell. Calls lasted between 90 seconds and over 20 minutes. Victims were convinced to launch remote sessions via Microsoft Quick Assist or install RemSupp (cloud-based RMM tool). After gaining remote access, attackers used PowerShell to download a backdoor into the compromised user's %AppData% folder. The backdoor profiled the system, established persistence, and provided continued remote access. Persistence mechanisms were disguised as Realtek and Windows audio components using registry entries named 'Realtek HD Audio,' 'Realtek Audio UHD,' and 'WinAudio life2.' In ransomware-leading incidents, additional remote access tools (DWAgent, AnyDesk) were installed and RDP was enabled for lateral movement. At least three intrusions led to Chaos ransomware deployment, with ransom notes named 'readme.chaos.txt.' In one incident, the time from initial Teams contact to ransomware deployment was under 17 hours. Files were encrypted simultaneously across compromised devices. The attackers likely exfiltrated data before deploying ransomware in at least one case. The attack chain was continually modified between February and May 2026, with changing malware filenames, persistence mechanisms, and deployment methods to evade detection. The Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed linked to former members of BlackSuit and Royal ransomware gangs, which were spinoffs of the Conti cybercrime syndicate. Approximately 95% of attacks targeted organizations in Canada (50%) and the United States (45%), across sectors including services, manufacturing, energy, and construction/engineering.

Mitigation steps:

1. Block or restrict external Microsoft Teams communications from unknown or unverified tenants, especially those using non-corporate domains. 2. Block or restrict Microsoft Quick Assist and unapproved RMM tools (RemSupp, DWAgent, AnyDesk) via application allowlisting or corporate blocklists. 3. Educate employees about vishing attacks via Microsoft Teams and the risk of granting remote access to unverified IT support personnel. 4. Monitor for suspicious PowerShell activity, especially file downloads to %AppData% directories. 5. Monitor registry for suspicious persistence entries disguised as audio drivers (e.g., 'Realtek HD Audio', 'Realtek Audio UHD', 'WinAudio life2'). 6. Block or alert on connections to known malicious domains: sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, supportsoft[.]top. 7. Monitor for unauthorized RDP enablement on endpoints. 8. Monitor for installation of unauthorized remote access tools (AnyDesk, DWAgent). 9. Implement data loss prevention (DLP) controls to detect large-scale data exfiltration prior to ransomware deployment. 10. Enforce strict policies around who can initiate external Teams calls and implement caller verification procedures for IT support requests. 11. Review Microsoft Teams external access settings and consider limiting or auditing external domain communications.

Affected products:

Microsoft Teams
Microsoft Quick Assist
RemSupp (remote monitoring and management tool)
DWAgent
AnyDesk
Windows (Remote Desktop Protocol)

Related links:

Related CVE's:

Related threat actors:

IOC's:

sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, supportsoft[.]top, readme.chaos.txt (ransom note filename), Persistence registry key: Realtek HD Audio, Persistence registry key: Realtek Audio UHD, Persistence registry key: WinAudio life2, Backdoor dropped to %AppData% folder, Fake persona: Anthony Brooks, Fake persona: Dylan Harper, Fake persona: Ethan Parker, Fake persona: Jason Mitchell

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page