Chaos in Teams Vishing
Sophos, Tuesday, July 28th, 2026
Sophos tracks STAC4749 using Teams vishing and custom malware to deploy Chaos ransomware within 17 hours.
Sophos details STAC4749, a threat group that ran a Microsoft Teams vishing campaign between February and June 2026 against dozens of North American organizations in services, manufacturing, energy, and construction. Attackers impersonated IT support staff from accounts on .top domains to trick victims into granting remote access through Quick Assist or RemSupp.
After the initial compromise, operators deployed custom Python and Golang malware that persisted via registry Run keys disguised as audio components, and maintained certificate-pinned command and control. The group selectively added DWAgent and AnyDesk for lateral movement.
At least three intrusions escalated to Chaos ransomware, with encryption beginning within 17 hours of initial access in some cases.