Fake IT support calls on Microsoft Teams are ending in ransomware within a day
A gang tracked as STAC4749 is phoning staff on Teams, pretending to be helpdesk, and locking company files with Chaos ransomware in under 17 hours.

Key points
- Sophos tracked a campaign called STAC4749 that hit dozens of North American organisations between February and June 2026.
- Attackers posed as IT helpdesk staff on Microsoft Teams calls, most lasting just two to three minutes, to talk employees into handing over remote access.
- At least three intrusions ended in Chaos ransomware, which locks a company's files until a payment is made, with one case going from first contact to encryption in under 17 hours.
- Roughly 95% of victims were in Canada (50%) and the United States (45%), across services, manufacturing, energy, and construction.
- Sophos links Chaos to former members of the BlackSuit and Royal ransomware crews, both spinoffs of the notorious Conti group.
A ransomware gang has spent five months phoning staff at North American companies over Microsoft Teams, pretending to be the IT helpdesk, and using those calls to break in and lock up the files.
Security firm Sophos calls the campaign STAC4749. Between February and June 2026, it hit dozens of organisations. At least three of those break-ins ended with Chaos ransomware being deployed across the victim's network.
In one case, only 17 hours passed between the first Teams call and files being encrypted.
How did the attackers get in?
They called employees on Microsoft Teams, pretending to be internal IT support, and talked them into launching a remote-control session. Most calls lasted two to three minutes. That was long enough.
The hook was familiar to anyone who has covered vishing, which is phone-based phishing where a scammer talks a target into doing something over a live call. What made STAC4749 interesting is the packaging.
Earlier Teams scams tended to use throwaway Microsoft tenants on the onmicrosoft.com domain. This crew registered IT-flavoured domains under the cheap .top top-level domain instead, names like sequrityupdate[.]top, scan-security[.]top and supportsoft[.]top. They paired each domain with a plausible-sounding helpdesk persona: Anthony Brooks, Dylan Harper, Ethan Parker, Jason Mitchell.
Once on the call, the fake technician steered the employee into opening Microsoft Quick Assist, a built-in Windows tool that lets someone else drive your computer. If Quick Assist was blocked, they switched to a cloud tool called RemSupp. From April onward they preferred RemSupp outright, probably because fewer companies had it on a blocklist.
Call it social engineering with a Teams skin. The remote-access tool is the payload delivery mechanism, and the human on the other end is the vulnerability.
What happened after the call?
Once the attacker had hands on the keyboard, they used PowerShell, a scripting tool built into Windows, to pull down a backdoor into the user's AppData folder. The malware profiled the machine and set up persistence so it would survive a reboot.
To hide, the persistence entries were named after real audio drivers: "Realtek HD Audio," "Realtek Audio UHD," "WinAudio life2." An admin glancing at a registry key would likely scroll past.
On the runs that ended in ransomware, the crew also installed DWAgent or AnyDesk as a spare key, and switched on Remote Desktop Protocol to hop between machines. Sophos says the attackers kept tweaking filenames and techniques through the spring to stay ahead of detection.
| Detail | Figure |
|---|---|
| Active period | February to June 2026 |
| Organisations targeted | Dozens |
| Confirmed ransomware cases | At least 3 |
| Fastest intrusion to encryption | Under 17 hours |
| Victims in Canada | 50% |
| Victims in United States | 45% |
Who is behind Chaos ransomware?
Sophos assesses STAC4749 is financially motivated and either deploys Chaos directly or works with its affiliates. Ransom notes land on victim machines as "readme.chaos.txt" and threaten to leak stolen data if payment is not made.
Chaos has been running as a ransomware-as-a-service operation since at least February 2025. Sophos and reporting by BleepingComputer link it to former members of the BlackSuit and Royal gangs, both offshoots of Conti.
Teams-based vishing is not new. Black Basta affiliates were pulling the same trick in late 2024, and the Iranian group MuddyWater has used Chaos as a smokescreen for espionage. Sophos says it found no link between STAC4749 and MuddyWater.
What should ordinary staff watch for?
If someone calls you on Teams claiming to be IT and asks you to open Quick Assist, AnyDesk or anything similar, hang up and phone your real helpdesk on a known number. Genuine IT teams do not cold-call from external accounts. That is the whole attack in one sentence.



