Teams Vishing Campaigns Hit North American Firms With Chaos Ransomware

Sophos tracked a Teams vishing campaign as STAC4749, where fake IT support calls led to Chaos ransomware encryption at North American firms in under 17 hours.
Table of Contents
    Add a header to begin generating the table of contents

    Threat actors impersonating IT support staff in Microsoft Teams calls have gained remote access to corporate devices and deployed Chaos ransomware against North American organizations. Sophos tracks the campaign as STAC4749, which targeted dozens of organizations across services, manufacturing, energy, and construction and engineering, with at least three intrusions leading to Chaos ransomware deployment and one attack reaching file encryption in less than 17 hours.

    STAC4749’s IT-Support Impersonation Moves From Teams Call to Encryption

    The attacks begin with external Microsoft Teams accounts impersonating IT helpdesk or support personnel in chats and voice calls. Observed calls lasted between 90 seconds and more than 20 minutes, with most running around two to two-and-a-half minutes. Sophos said STAC4749 diverges from past Teams campaigns by creating IT-themed domains under the “.top” top-level domain, including sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top, paired with fake IT support personas such as Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell.

    Fake Helpdesk Personas on .top Domains and the Quick Assist-to-RemSupp Shift

    The goal of the calls was to convince employees to launch a remote support session using Microsoft Quick Assist or to install another remote management tool. Attackers initially preferred Quick Assist but primarily used the cloud-based RemSupp tool beginning in April, likely because it is less likely to sit on corporate application blocklists. After gaining remote access, attackers used PowerShell to download a backdoor into the user’s %AppData% folder that profiled the system, established persistence, and provided continued access.

    Backdoor Persistence Disguised as Realtek and Windows Audio Components

    Persistence registry entries were disguised as Realtek and Windows audio components, using names such as “Realtek HD Audio,” “Realtek Audio UHD,” and “WinAudio life2.” In incidents that led to Chaos ransomware, attackers also installed remote access software such as DWAgent or AnyDesk for backup access and attempted to enable Remote Desktop Protocol to move laterally. Sophos noted that attackers continually modified the attack chain between February and May, changing malware filenames, persistence mechanisms, and deployment methods to avoid detection.

    At Least Three Chaos Ransomware Deployments in the Campaign

    At least three STAC4749 compromises led to Chaos ransomware, with at least one case in which attackers likely stole data before deploying ransomware. Ransom notes named “readme.chaos.txt.” The campaign targeted dozens of organizations, with roughly 95 percent located in North America, split about evenly between Canada at 50 percent and the United States at 45 percent.

    The Chaos RaaS Lineage and the MuddyWater Distinction

    Sophos assesses with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates. Chaos ransomware-as-a-service is believed to be linked to former members of the BlackSuit and Royal ransomware gangs, themselves spinoffs of the Conti syndicate. Sophos found no evidence connecting STAC4749 to MuddyWater, the Iranian group previously seen using Chaos ransomware as a decoy, which keeps this campaign separate from that earlier pattern.

    What the 17-Hour Encryption Timeline Shows About Voice-Based Initial Access

    The speed from initial access to encryption, under 17 hours in at least one case, points to a playbook in which the attacker front-loads the human element and compresses the technical steps. Once the employee grants a remote support session, the operators can run the backdoor, test persistence, install backup remote access, and execute ransomware within a single working day, a pace that gives a flat-footed security team little time to notice unusual support tooling. The campaign’s preference for RemSupp over Quick Assist also shows an awareness of endpoint blocklists, suggesting the operators iterate based on what defenders are already catching.

    The constant modification of the chain between February and May, with changing malware filenames, persistence mechanisms, and deployment methods, adds a detection challenge on top of the social engineering. A signature written for one month’s variant may be obsolete by the time it ships to a SOC, which is why the common denominator across the campaign is not a file hash but the Teams-based voice interaction that precedes every deployment. Organizations that have not restricted external Teams calls, or that rely on the application’s default settings for external federated access, are effectively leaving the front door that STAC4749 uses.

    Defender Guidance for External Teams Communication

    No vendor patch applies to the campaign. Sophos recommends restricting external Teams communication, verifying IT-support identities through out-of-band channels, and blocking or restricting Quick Assist and RemSupp unless they are genuinely required. Monitoring should cover backdoors placed in %AppData%, registry entries disguised as audio components, DWAgent or AnyDesk installs, and attempts to enable Remote Desktop Protocol. The combination of social engineering over voice and remote support tooling means that identity verification, not malware detection, is the first line of defense against this campaign.

    Related Posts