Fake IT support calls on Microsoft Teams are ending in ransomware within a day
A gang tracked as STAC4749 is phoning staff on Teams, pretending to be helpdesk, and locking company files with Chaos ransomware in under 17 hours.

Key points
- Sophos tracked a campaign called STAC4749 that hit dozens of North American organisations between February and June 2026.
- Attackers posed as IT helpdesk staff on Microsoft Teams calls, most lasting two to two-and-a-half minutes, to talk employees into handing over remote access.
- At least three intrusions ended in Chaos ransomware, which locks a company's files until a payment is made, with one case going from first contact to encryption in under 17 hours.
- Roughly 95% of victims were in Canada (50%) and the United States (45%), across services, manufacturing, energy, construction and engineering.
- Sophos links Chaos to former members of the BlackSuit and Royal ransomware crews, both spinoffs of the notorious Conti group.
A ransomware gang spent five months phoning staff at North American companies over Microsoft Teams, pretending to be the IT helpdesk, and using those calls to break in and lock up the files.
Security firm Sophos calls the campaign STAC4749. Between February and June 2026, it hit dozens of organisations. At least three of those break-ins ended with Chaos ransomware deployed across the victim's network. We first covered the Chaos crew on 23 July, when researchers found a backdoor that hides attacker commands inside the victim's own browser; this latest report shows the same operation pivoting to phone-based trickery.
In one case, only 17 hours passed between the first Teams call and files being encrypted.
How did the attackers get in?
They called employees on Microsoft Teams, pretending to be internal IT support, and talked them into launching a remote-control session. Most calls lasted two to two-and-a-half minutes. That was long enough.
The hook is a form of vishing, phone-based phishing where a scammer talks a target into acting over a live call. What made STAC4749 worth watching is the packaging. Earlier Teams scams tended to use throwaway Microsoft tenants on the onmicrosoft.com domain. This crew registered IT-flavoured domains under the cheap .top top-level domain instead: names like sequrityupdate[.]top, scan-security[.]top and supportsoft[.]top. They paired each domain with a plausible-sounding helpdesk persona: Anthony Brooks, Dylan Harper, Ethan Parker, Jason Mitchell.
Once on the call, the fake technician steered the employee into opening Microsoft Quick Assist, a built-in Windows tool that lets someone else drive your computer. If Quick Assist was blocked, they switched to a cloud tool called RemSupp. From April onward they preferred RemSupp outright, probably because fewer companies had it on a blocklist.
Call it social engineering with a Teams skin. The remote-access tool is the payload delivery mechanism, and the human on the other end is the vulnerability.
What happened after the call?
Once the attacker had hands on the keyboard, they used PowerShell, a scripting tool built into Windows, to pull down a backdoor into the user's AppData folder. The malware profiled the machine and set up persistence so it would survive a reboot.
To hide, the persistence entries were named after real audio drivers: "Realtek HD Audio," "Realtek Audio UHD," "WinAudio life2." An admin glancing at a registry key would likely scroll past.
On the runs that ended in ransomware, the crew also installed DWAgent or AnyDesk as a spare key, and switched on Remote Desktop Protocol to hop between machines. Sophos notes the attackers kept tweaking filenames and techniques through the spring to stay ahead of detection.
| Detail | Figure |
|---|---|
| Active period | February to June 2026 |
| Organisations targeted | Dozens |
| Confirmed ransomware cases | At least 3 |
| Fastest intrusion to encryption | Under 17 hours |
| Victims in Canada | 50% |
| Victims in United States | 45% |
Who is behind Chaos ransomware?
Sophos assessed, with high confidence, that STAC4749 was financially motivated and either deployed Chaos directly or coordinated with affiliates. Ransom notes land on victim machines as "readme.chaos.txt" and threaten to leak stolen data if payment isn't made.
Chaos has been running as a ransomware-as-a-service operation since at least February 2025. Sophos links it to former members of the BlackSuit and Royal gangs, both offshoots of Conti.
Teams-based vishing isn't new. Black Basta affiliates were pulling the same trick in October 2024, and the Iranian group MuddyWater has used Chaos as a smokescreen for espionage. Sophos found no link between STAC4749 and MuddyWater.
Should you worry about your own staff?
If someone calls on Teams claiming to be IT and asks you to open Quick Assist or AnyDesk, hang up and phone your real helpdesk on a known number. Genuine IT teams don't cold-call from external accounts. A Sophos survey we reported in July found phishing and social engineering now cause half of all ransomware incidents, which makes the human layer the one worth defending hardest.



