Disguised as IT support on Teams, they install ransomware in less than 17 hours

Hackers posing as IT support on Microsoft Teams exploited Quick Assist to install Chaos ransomware in under 17 hours, targeting North American organizations.

Disguised as IT support on Teams, they install ransomware in less than 17 hours
Ransomware

Illustrative image generated with AI

On July 30, Sophos disclosed a vishing campaign that targeted dozens of North American organizations between February and June 2026. The group tracked as STAC4749 primarily struck Canada (50% of cases) and the United States (45%), focusing on services, manufacturing, energy, and construction. At least three companies suffered full data encryption with the Chaos ransomware. The minimum observed time from the first Microsoft Teams contact to ransomware activation was under seventeen hours.

Two-minute trap: fake IT, “.top” domains, and a Teams call

Attackers reached out to employees directly on Microsoft Teams using external tenants registered with “.top” top-level domains – for example sequrityupdate[.]top. They posed as internal technical support personnel, using fictitious names like Anthony Brooks or Dylan Harper. Calls could last just two minutes. In that brief conversation, they convinced the victim to initiate a remote assistance session by playing on the urgency of a security intervention.

Remote access was achieved via Microsoft Quick Assist, the built-in Windows support tool. In cases where Quick Assist was blocked by company policies, the attackers switched to RemSupp, a cloud-based remote management service. The use of RemSupp became prevalent starting in April 2026, highlighting a rapid adaptation to encountered defenses.

Silent escalation: PowerShell, fake audio components, and side channels

Once initial access was gained, the operators executed PowerShell commands to download a backdoor into the %AppData% folder. Persistence was disguised under names that mimicked legitimate audio components – “Realtek HD Audio” or “WinAudio life2” – a choice that reduced the likelihood of alarms during routine checks.

In cases that evolved to ransomware, the attack did not stop there. Additional remote access tools such as DWAgent and AnyDesk were installed, and the RDP protocol was enabled to move laterally across the network. The combination of legitimate channels and widely used tools made it harder to separate hostile traffic from administrative activity.

Final payload: Chaos ransomware, simultaneous encryption, and Conti links

At least three compromises ended with the distribution of the Chaos ransomware. Encryption occurred simultaneously across multiple machines, with the interval between the Teams contact and encryption in one incident just over 16 hours. Sophos also reports probable data exfiltration, though no details on the theft methods were released.

Chaos is a ransomware-as-a-service active since February 2025. Analysis ties it to former members of the BlackSuit/Royal group and the Conti galaxy. Sophos explicitly rules out any link to the use of this ransomware by MuddyWater. The speed of the entire chain, combined with effective obfuscation practices, shows the experience of the affiliates behind this campaign.

Cutting the bridges: mitigations against vishing and ransomware via Teams

The evidence gathered points to concrete countermeasures that organizations can apply immediately:

  • Block Microsoft Teams communications from untrusted external tenants, especially those with “.top” domains, and disable Quick Assist if it is not essential.
  • Add RemSupp and other unauthorized remote management tools to blocklists; only permit approved RMM solutions.
  • Train employees to reject unsolicited IT support calls or chats and never grant remote access without out-of-band verification.
  • Monitor suspicious PowerShell executions, the appearance of new executables in %AppData%, and persistence registry entries with misleading names.
  • Restrict RDP usage, segment the network to hinder lateral movement, and strengthen exfiltration controls.
  • Conduct periodic attack simulations to verify that SIEM and EDR rules capture sequences similar to those described.

The STAC4749 campaign shows that a legitimate cloud infrastructure, an inexpensive domain, and two minutes on the phone can be enough to pave the way for destructive ransomware. Blocking ungoverned access to remote assistance tools sharply reduces the maneuvering room of attackers who can switch tools within weeks.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →