Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Flash Player Installer Uses Microsoft Cert to Deploy AtlasRAT
July 30, 2026
GitLab Patches Critical Flaws Letting Attackers Leak Data, Alter Pipelines
July 30, 2026
Linux Cryptomining Campaign Leverages PAM to Conceal XMRig Botnet
July 30, 2026
Home/Threats/Critical Microsoft Teams Vulnerability Lets Attackers Install Ransomware
Threats

Critical Microsoft Teams Vulnerability Lets Attackers Install Ransomware

Key Takeaways Attackers are leveraging Microsoft Teams voice phishing to gain initial access to corporate networks. The campaign, identified as STAC4749, impersonates IT support to trick employees...

Jennifer sherman
Jennifer sherman
July 30, 2026 4 Min Read
2 0

Key Takeaways

  • Attackers are leveraging Microsoft Teams voice phishing to gain initial access to corporate networks.
  • The campaign, identified as STAC4749, impersonates IT support to trick employees into granting remote access.
  • Once access is secured, attackers deploy Chaos ransomware, often within 17 hours of initial compromise.
  • The threat actors continuously evolve their tactics, using custom malware and legitimate remote administration tools to evade detection.
  • Organizations must implement robust user awareness training and monitor for suspicious activity on collaboration platforms.

A disturbing new trend reveals that a brief Microsoft Teams call can now serve as the entry point for a full-scale ransomware attack. Cybercriminals, masquerading as internal IT support, are manipulating employees into granting remote access to their systems. This initial foothold is then exploited to propagate across networks and deploy Chaos ransomware, according to recent analysis.

Table Of Content

  • Key Takeaways
  • A Two-Minute Microsoft Teams Call
  • Encryption Follows Quickly
  • What You Should Do

The campaign, designated STAC4749, has targeted dozens of organizations across North America between February and June 2026. Alarming data shows that most of these deceptive calls lasted a mere two to two-and-a-half minutes, underscoring the speed and effectiveness with which social engineering can lead to severe network compromise.

Analysts from Sophos have identified this as a financially motivated operation. It skillfully combines voice phishing via Teams, bespoke malicious software, and legitimate remote administration utilities. Sophos said in a report that the attackers consistently altered their methodologies to circumvent existing detection mechanisms.

These incidents highlight a growing vulnerability for organizations that inherently trust widely used collaboration platforms. The attackers bypass traditional attack vectors like malicious attachments or fake websites by simply convincing users to approve a remote-support session during a seemingly credible call.

A Two-Minute Microsoft Teams Call

The STAC4749 operators initiated their attacks through Microsoft Teams chats and voice calls, expertly impersonating helpdesk or IT personnel. They utilized convincing employee-like names and IT-themed cloud domains, enhancing the credibility of their spoofed accounts, especially to users accustomed to receiving support requests through online channels.

Attackers primarily sought access via Microsoft Quick Assist, a built-in Windows remote-support utility. If Quick Assist was unavailable, they pivoted to alternative remote-management applications. This tactic mirrors the dangers observed in other Teams Quick Assist impersonation attacks, where trusted workplace tools are leveraged to grant attackers control over an endpoint in minutes.

Upon gaining approval for the remote session, the attackers executed commands to gather system information, identify installed security products, and establish persistent access. They also attempted to enable Remote Desktop Protocol (RDP), facilitating lateral movement to other devices after the initial compromise of an employee’s workstation.

Initially, the attackers employed a custom loader. However, they soon transitioned to a Python-based backdoor delivered directly through the remote session. This tactical evolution streamlined their intrusion process, enabling faster operations. Furthermore, by frequently changing filenames and persistence methods, they rendered simple signature-based defenses less effective.

Encryption Follows Quickly

Once persistent access was established, STAC4749 deployed additional tools to maintain control and expand their presence within the victim’s environment. In several documented cases culminating in Chaos ransomware deployment, the operators leveraged secondary remote-access channels and a reverse proxy tool to communicate with internal network systems.

At least three confirmed STAC4749 compromises resulted in the deployment of Chaos ransomware. Encryption across endpoints occurred almost simultaneously. In one particularly rapid incident, the entire attack chain, from initial access to ransomware deployment, transpired in under 17 hours, leaving security teams minimal time for detection and containment.

Chaos has been active as a ransomware-as-a-service (RaaS) operation since at least February 2025. Its use of voice phishing and legitimate remote-management tools aligns with broader trends in recent Chaos ransomware activity, where threat actors prioritize stealthy initial access before initiating the disruptive encryption phase.

What You Should Do

  • Verify Unexpected Requests: Treat any unexpected external Teams messages and calls as suspicious, particularly if they request remote-support software activation, application installation, or access sharing.
  • Independent Verification: Employees must independently verify all support requests through established, known internal contact channels rather than relying solely on the caller’s asserted identity.
  • Monitor Teams Activity: Security teams should actively monitor Microsoft Teams activity, suspicious PowerShell usage, unusual command-line executions, and unauthorized remote administration or tunneling tools.
  • Review Persistence Locations: Regularly review common Windows persistence locations, such as registry Run keys, to uncover hidden access mechanisms before ransomware deployment.
  • Restrict Software Execution: Implement controls to restrict unauthorized software execution and tightly manage the use of remote-support tools within the organization.
  • User Awareness Training: Conduct regular and comprehensive user awareness training, emphasizing the dangers of social engineering, especially concerning trusted cloud services like Teams and Google Drive, which attackers increasingly exploit to bypass traditional email-centric defenses.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingransomwareSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Claude AI Outage Displays “Request Failed With 529 Overloaded” Error

Next Post

Linux Cryptomining Campaign Leverages PAM to Conceal XMRig Botnet

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Node.js Patches 11 Vulnerabilities, Some Critical, Allowing Server Crashes
July 30, 2026
Cybercrime Platform Leverages Helpdesk Calls for Enterprise Account Takeovers
July 30, 2026
Copybara Android RAT Spreads via Fake N26 Support Calls to Control Banking Apps
July 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us