TempMail Ninja
//

Chaos Ransomware Delivered via Microsoft Teams Vishing Campaign

3 min read
TempMail Ninja
Chaos Ransomware Delivered via Microsoft Teams Vishing Campaign

In an era where enterprise email defenses have reached unprecedented maturity, cybercriminals are pivoting away from traditional inbox phishing toward high-trust collaboration environments. On July 28, 2026, cybersecurity research firm Sophos published a detailed threat advisory exposing an active social engineering and digital extortion campaign operated by a financially motivated threat cluster tracked as STAC4749. Active between February and June 2026 across dozens of North American organizations, this cluster bypasses traditional email security filters by conducting voice phishing—or vishing—directly through Microsoft Teams calls. By posing as internal IT helpdesk specialists, STAC4749 operators trick personnel into granting remote access or executing malicious scripts, culminating in systematic data exfiltration and the deployment of Chaos ransomware.

This campaign underscores a profound operational shift in modern cybercrime. As enterprises rely heavily on unified collaboration platforms to support distributed workforces, threat actors are aggressively exploiting default tenant configurations to establish direct lines of communication with target employees. The STAC4749 campaign highlights how combining social engineering, custom modular post-exploitation frameworks, and Chaos ransomware can blindside defenders who remain overly focused on perimeter email security.

Deconstructing STAC4749: Teams Vishing and Helpdesk Impersonation

The operational playbook of STAC4749 relies on meticulous preparation and psychological manipulation. Rather than launching broad-spectrum phishing blasts, the threat cluster conducts pre-attack reconnaissance to identify specific operational roles within target organizations. The initial access phase relies on structured social engineering designed to establish credibility before initiating direct contact.

To build trust, STAC4749 registers IT-themed cloud domains and constructs custom personas mimicking internal support staff or third-party IT service providers. The primary mechanics of the attack unfold through the following sequence:

  • Infrastructure Setup: Attackers create dedicated Microsoft Office 365 tenant accounts hosted on domains tailored with IT support terminology and subtle typosquatting.
  • Federation Exploitation: STAC4749 leverages default Microsoft 365 tenant configurations that permit external domains to initiate direct chats and voice calls with internal enterprise users.
  • Vishing Engagement: Operators launch direct Microsoft Teams voice calls to target employees. Posing as IT support personnel, attackers claim to be resolving urgent, fictitious technical issues such as security certificate updates, pending software patches, or active system anomalies.
  • Access Acquisition: The adversary instructs the victim to grant remote desktop control through native Teams tools, remote management software, or Microsoft Quick Assist. Alternatively, victims are convinced to download and run custom malicious setup scripts.

By conducting interactions over voice calls within a trusted corporate application, STAC4749 bypasses the suspicion attached to unverified email links or external attachments, causing employees to skip standard identity verification steps.

Modular Post-Exploitation and Defense Evasion

Once initial access is granted, STAC4749 transitions rapidly from social engineering to automated post-exploitation. Operators deploy a modular toolset designed to maintain persistent access, evade endpoint controls, and enable lateral movement across the enterprise network.

Central to STAC4749’s technical suite is a specialized loader that executes in-memory payloads while bypassing endpoint detection and response (EDR) agents. The loader utilizes API unhooking and process injection—targeting legitimate system processes such as explorer.exe—to mask execution. A persistent backdoor is then established to maintain encrypted Command and Control (C2) communication with external servers.

To ensure covert access over extended operational windows, STAC4749 employs several key

TN

Written by

TempMail Ninja

Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.