VYPR
breachPublished Jul 30, 2026· 1 source

Chaos Ransomware Spreads Via Microsoft Teams Voice Phishing

Attackers are leveraging Microsoft Teams voice calls to trick employees into granting remote access, enabling rapid deployment of Chaos ransomware.

Threat actors are increasingly sophisticated in their social engineering tactics, with a recent campaign dubbed STAC4749 demonstrating how a brief Microsoft Teams call can initiate a full-blown ransomware attack. Attackers impersonate IT support staff, using convincing lures to persuade employees to grant remote access to their systems. This method bypasses traditional defenses like malicious email attachments or links, exploiting the trust users place in internal communication platforms.

The campaign, which targeted North American organizations between February and June 2026, saw attackers initiate contact through Microsoft Teams chats and voice calls. They employed employee-like names and IT-themed domain names to appear legitimate. The primary goal was to gain remote access, often through Microsoft's built-in Quick Assist tool or alternative remote management applications when Quick Assist was unavailable. Sophos researchers noted that the attackers continuously adapted their techniques to evade detection, highlighting the evolving nature of cyber threats.

Once remote access was granted, the threat actors executed commands to gather system information, identify security software, and establish persistent access. They also attempted to enable Remote Desktop Protocol (RDP) to facilitate lateral movement across the compromised network. Initially, a custom loader was used, but the attackers evolved to deliver a Python-based backdoor directly through the remote session, streamlining the intrusion process and making detection more difficult.

The speed at which these attacks progress is alarming. In several instances where Chaos ransomware was deployed, the entire process from initial access to encryption occurred in under 17 hours. This rapid timeline leaves security teams with minimal time to detect, contain, and remediate the threat. The attackers utilized secondary remote access channels and reverse proxy tools to maintain control and expand their reach within the victim's environment before initiating the destructive encryption phase.

Chaos ransomware has been operating as a ransomware-as-a-service (RaaS) since at least February 2025. Its adoption of voice phishing and reliance on legitimate remote management tools aligns with broader trends observed in recent Chaos ransomware activity, where attackers prioritize stealthy initial access before launching their disruptive payload. This particular campaign underscores the significant risk posed by the convergence of collaboration platforms and social engineering.

To combat this threat, organizations are advised to treat unexpected external Teams messages and calls with suspicion, especially those requesting remote support or software installation. Employees should independently verify support requests through established internal channels rather than relying on the caller's purported identity. Security teams should enhance monitoring for suspicious activity within Teams, unusual PowerShell usage, unauthorized remote administration tools, and common Windows persistence mechanisms.

Implementing controls to restrict unauthorized software execution and carefully managing access to remote support tools are crucial mitigation strategies. Furthermore, continuous user awareness training remains paramount, as attackers increasingly leverage trusted cloud services and convincing social engineering to circumvent traditional email-centric security measures. The campaign's success highlights the need for a multi-layered security approach that addresses both technical vulnerabilities and human factors.

The campaign's technical indicators include a range of IT-themed domains used for command and control, specific payload download locations, and various file name patterns for initial loaders, backdoors, and implants. These indicators, detailed by Sophos, are vital for threat intelligence and detection efforts.

Synthesized by Vypr AI