"Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates," Sophos reported.
How STAC4749 used Microsoft Teams to gain remote access
Sophos says the campaign began with external Microsoft Teams accounts impersonating IT helpdesk or support staff in Teams chats and voice calls to targeted employees. The calls—observed to last between 90 seconds and more than 20 minutes, with most completing in roughly two to two-and-a-half minutes—aimed to convince staff to start remote support sessions or install remote monitoring and management (RMM) software.
Actors used IT-themed domains under the ".top" top-level domain (examples include sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top) and paired those domains with fake support personas such as Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell. The immediate goal was to get targets to launch Microsoft Quick Assist or to install a third-party RMM tool.
Tools and persistence: Quick Assist, RemSupp, PowerShell, and disguised registry entries
Sophos reports the attackers initially preferred Microsoft Quick Assist and used the cloud-based RemSupp tool when Quick Assist was unavailable or blocked. Beginning in April, the campaign shifted to primarily using RemSupp—Sophos notes this may have been because RemSupp was less likely to appear on corporate application blocklists.
After gaining remote control, the adversaries executed PowerShell to download a backdoor into the compromised user's %AppData% folder. The malware profiled the system, established persistence, and provided continued remote access. To make persistence appear legitimate the attackers created malicious registry entries disguised as Realtek and Windows audio components, using names such as "Realtek HD Audio," "Realtek Audio UHD," and "WinAudio life2."
In intrusions that later resulted in ransomware, Sophos observed operators installing additional remote access software such as DWAgent or AnyDesk for backup access and attempting to enable Remote Desktop Protocol (RDP) on compromised devices to move laterally within networks.
From initial contact to Chaos ransomware: rapid escalation and data theft
Sophos tracked dozens of these intrusions between February and June 2026 under the designation STAC4749. At least three compromises led to deployment of Chaos ransomware. In at least one case, Sophos says less than 17 hours elapsed from the initial Microsoft Teams contact to the deployment of ransomware that encrypted files simultaneously across compromised devices.
Ransom notes named "readme.chaos.txt" were left on affected systems. BleepingComputer viewed Chaos ransom notes that all include the same text claiming data theft and warning the data would be leaked if a ransom was not paid. Sophos adds that in at least one of the Chaos-linked incidents the attackers likely exfiltrated data before encryption.
Sophos further reports that the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal gangs, which were spinoffs from the Conti cybercrime syndicate.
Geography and sectors targeted by STAC4749
Roughly 95% of the attacks targeted organizations in North America: about 50% in Canada and about 45% in the United States, Sophos found. The campaign reached organizations across multiple sectors, with the largest numbers of attacks hitting services, manufacturing, energy, and construction and engineering.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Sophos documents continual modification of the attack chain between February and May—changes to malware filenames, persistence mechanisms, and deployment methods—intended to evade detection. Teams should note the actors' use of multiple remote-access mechanisms (Quick Assist, RemSupp, DWAgent, AnyDesk) and the use of audio-component–named registry entries to mask persistence.
- Procurement and application-control owners: The operators shifted to RemSupp beginning in April, possibly because it was less likely to be included in corporate application blocklists. That fact highlights the operational impact of what tools are allowed or blocked and the value of reviewing RMM and remote-access approvals against observed abuse patterns.
- End users: Calls were short and socially engineered to appear as routine IT support; most completed in about two to two-and-a-half minutes. Sophos observed external Teams accounts impersonating IT staff and using plausible IT-themed domains and names to prompt targets to grant access—behavior ordinary employees may mistake for legitimate support.
Sophos found no evidence linking STAC4749 to the MuddyWater activity that previously used Microsoft Teams, and the company assesses the STAC4749 operations as financially motivated—either directly deploying Chaos ransomware or coordinating with affiliates. The rapid progression from a Teams call to full-file encryption in at least one incident crystallizes the campaign's risk: short social-engineering interactions, a small set of remote-access tools, and rapid technical follow-through can be enough to deliver modern ransomware and possible data theft.
Read the original report: https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/




