Chaos’ DLS
At a glance
| Actor | STAC4749 (unattributed threat cluster) |
| Activity | Teams vishing, remote access, ransomware |
| Targets | Dozens of North American organizations (Canada, U.S.) |
| Scale | At least three Chaos ransomware deployments; encryption in under 17 hours in one case |
| Status | No public law-enforcement action; assessed as financially motivated |
| Source | Sophos X-Ops |
TL;DR
Sophos has detailed a Microsoft Teams vishing campaign that ends in ransomware. The operators posed as IT support, talked victims into a remote session, then deployed Chaos ransomware. In one case, encryption began less than 17 hours after the first call.
What happened
Between February and June 2026, a threat cluster tracked as STAC4749 targeted dozens of North American organizations. The attack always started with a Microsoft Teams vishing call. An operator posed as helpdesk or IT support and asked for remote access.
Most calls were short. Sophos observed sessions from 90 seconds to more than 20 minutes, though most ran two to two-and-a-half minutes. The goal was simple: get the victim to launch a remote-support tool.
The operators favored Microsoft Quick Assist first. When that was blocked, they switched to a cloud RMM tool called RemSupp. Since April, they appeared to prefer RemSupp, likely to dodge application blocklists.
Fake IT support, real .top domains
Unlike earlier Teams abuse, STAC4749 did not spoof onmicrosoft[.]com tenants. Instead, the operators built IT-themed cloud accounts on the “.top” domain space. Plausible support personas made the accounts look legitimate.
Sophos frames the wider shift plainly. According to the report, “Teams vishing has become an increasingly common initial access vector.” MDR cases involving malicious Microsoft 365 activity climbed sharply through early 2026.
The malware chain
Once inside, the operators opened PowerShell and pulled payloads from attacker web servers. Early intrusions used a custom loader that profiled the host and fetched a Python backdoor. By mid-April, they often skipped the loader and grabbed the backdoor directly.
The backdoor then retrieved Go-based implants for encrypted command and control. For persistence, the malware planted registry Run keys disguised as Realtek or WinAudio components. Some samples added Startup shortcuts hidden behind names like “OneDriveUpdate.”
The operators also segmented their infrastructure. Several implants carried hard-coded certificate authorities, so each payload only talked to matching servers.
Who is behind it
Attribution stays open. Sophos assesses with high confidence that STAC4749 was financially motivated. The group either deployed Chaos ransomware directly or worked with affiliates.
The Chaos ransomware-as-a-service brand has run since at least February 2025. It was reportedly launched by former members of the BlackSuit operation. However, Sophos is cautious about pointing further.
Rapid7 suggested in May 2026 that Chaos might serve as a false flag for the Iranian group MuddyWater. Sophos found no evidence tying STAC4749 to that group. One mistyped command hinted at a Russian keyboard layout, yet the report states plainly that “there is insufficient evidence for attribution.”
Impact and scale
The targeting skewed hard toward North America. Canada made up about half of observed cases, while the U.S. added another 44 percent. Services, manufacturing, and energy took the heaviest hits.
Legal targets stood out. Every law firm hit specialized in intellectual property work. At least three compromises ended in Chaos ransomware, with data theft likely in one case.
How to stay protected
Treat unexpected Teams calls from outside your org with suspicion. A real helpdesk does not cold-call staff to install remote tools. So verify any such request through a known internal channel first.
On the technical side, restrict external Teams contact and lock down Quick Assist and RMM tools. Also watch PowerShell activity, audit registry Run keys, and train staff to report odd support calls. These steps break the chain before ransomware lands.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.