Microsoft Teams IT Support Scams Lead to Chaos Ransomware Attacks
Threat actors are posing as corporate IT support workers on Microsoft Teams to gain remote access to employee devices and deploy Chaos ransomware.
Sophos tracks the campaign as STAC4749. The security company observed dozens of attempted attacks against organizations in the United States and Canada between February and June 2026. At least three incidents ended with ransomware encryption.
Attackers impersonate IT staff on Microsoft Teams
The attackers contacted employees through external Microsoft Teams accounts. During chats and voice calls, they introduced themselves as helpdesk technicians or members of the company’s IT department.
They then claimed that they needed access to the employee’s computer to resolve a technical problem. Their goal was to persuade the target to approve a remote support session without verifying the request through an internal channel.
Once an employee accepted the request, the attackers gained direct access to the device and began installing additional tools.
RemSupp replaces Microsoft Quick Assist in later attacks
Early versions of the campaign relied heavily on Microsoft Quick Assist, a legitimate Windows support feature that allows another person to view or control a computer remotely.
When Quick Assist was blocked or unavailable, the attackers instructed victims to install other remote management software. They increasingly relied on the cloud-based RemSupp service from April onward.
Sophos believes RemSupp may have become the preferred option because fewer corporate application blocklists recognized it. Using legitimate remote support software also helped the attackers avoid deploying obviously malicious tools during the first stage of the attack.
PowerShell downloads a persistent backdoor
After gaining remote access, the attackers used PowerShell commands to download a backdoor into the victim’s %AppData% folder.
The malware gathered information about the compromised system, created persistence mechanisms, and maintained access after the original Teams or remote support session ended.
To make the activity appear legitimate, the attackers created registry entries with names that resembled Windows audio components. Observed names included Realtek HD Audio, Realtek Audio UHD, and WinAudio life2.
These entries allowed the malware to start automatically while making it harder for employees and administrators to identify the suspicious process.
Attackers install multiple remote access tools
In incidents that progressed to ransomware, the group installed additional remote access applications, including DWAgent and AnyDesk.
These tools provided backup access if defenders interrupted the original connection. The attackers also tried to enable Remote Desktop Protocol, which could help them access other systems and move across the corporate network.
Sophos observed repeated changes to the attack chain between February and May. The operators adjusted their tools, commands, and persistence methods as security products began detecting earlier versions.
Chaos ransomware encrypted multiple systems at once
At least three STAC4749 attacks resulted in Chaos ransomware deployment. During these incidents, the ransomware encrypted files across several compromised computers at approximately the same time.
Evidence from at least one attack suggests that the group may have stolen corporate data before starting encryption. This would allow the attackers to pressure the victim with both data exposure and system disruption.
Sophos assesses the campaign as financially motivated. The operators may deploy ransomware themselves or provide access to separate ransomware affiliates after compromising a network.
Other threat groups have also used Microsoft Teams for social engineering. The Iranian state-backed MuddyWater group has used Teams and fake ransomware activity to conceal espionage operations.
Chaos-related campaigns have also used other techniques. In a separate operation, Chaos ransomware used msaRAT to disguise malicious traffic inside Chrome and Edge.
How organizations can block Teams vishing attacks
Companies should limit external Microsoft Teams communications or closely monitor messages and calls from accounts outside the organization.
Employees should never approve an unexpected remote support request without confirming it through an official internal contact method. IT departments should also clearly explain which tools their technicians use and how legitimate support requests begin.
Security teams should block or restrict Quick Assist, RemSupp, AnyDesk, DWAgent, and similar software on systems that do not require remote administration.
Organizations should monitor unusual PowerShell activity, including unexpected downloads or encoded commands, as well as the installation of new or unauthorized remote management applications. These behaviors can indicate that an attacker has gained initial access and is attempting to establish control over a system.
They should also watch for suspicious registry entries that mimic legitimate audio software, attempts to enable Remote Desktop Protocol, and external Microsoft Teams accounts posing as internal support staff. Together, these indicators can help identify social engineering and post-compromise activity early in an attack chain.
In other security news, Microsoft is struggling to address vulnerabilities identified by Anthropic’s Claude Mythos. As security research becomes more automated, attackers may also find and exploit software weaknesses more quickly.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages