Teams vishing is now a ransomware on-ramp
BleepingComputer · Lawrence Abrams · source ↗
Sophos has documented a campaign it tracks as STAC4749 in which attackers pose as IT helpdesk staff over Microsoft Teams chats and voice calls, talk employees into starting a remote-support session, and — in at least three cases — end up deploying Chaos ransomware. The campaign hit dozens of North American organizations between February and June 2026, with roughly 95% of targets in Canada and the U.S. Most of the calls ran two to two-and-a-half minutes. In one intrusion, less than 17 hours separated the first Teams contact from file encryption.
What makes this worth a note is the mechanics of the voice channel itself. STAC4749 moved off Microsoft’s own onmicrosoft.com tenants and stood up IT-themed .top domains — sequrityupdate[.]top, scan-security[.]top, corp-connect[.]top — paired with consistent fake-technician personas. That’s the same trust-manufacturing problem the branded-calling and call-authentication world keeps circling: a voice contact arrives wearing an identity the recipient has no cheap way to verify, and the whole attack turns on the two minutes before anyone thinks to check. The channel is Teams rather than the PSTN, but the failure is identical — no attestation on who’s actually calling.
The through-line to watch: vishing keeps graduating from nuisance to initial-access vector for the most expensive outcomes on the board. Chaos itself is a ransomware-as-a-service operation Sophos links to former BlackSuit and Royal members, both Conti spinoffs. The voice call is no longer the scam; it’s the door the scam walks through.