Teams Vishing Unleashes Chaos: The STAC4749 Attack Strategy
If an unknown technician named "Anthony Brooks" calls your Microsoft Teams account asking to fix a pending corporate update, hang up right away. Between February and June 2026, a threat group tracked by Sophos as STAC4749 targeted dozens of North American organizations using direct voice phishing—or vishing—over Microsoft Teams. These weren't trivial password-reset attempts. In at least three confirmed intrusions, short voice chats escalated into complete network file encryption via Chaos ransomware. In one instance, the gap between initial contact and company-wide file locking was under 17 hours.
This campaign exposes a major hole in corporate access management. Enterprise security teams spend millions hardening perimeters while leaving internal chat platforms open to external tenant calls. Threat actors know your employees trust internal collaboration tools. By blending live voice social engineering with legitimate remote support software, STAC4749 bypassed legacy email filters and EDR blocklists without raising early alerts.
STAC4749 Attack Playbook: How Fake Teams Calls Escalate AI Cybersecurity Threats
Understanding how STAC4749 operates means looking beyond standard phishing metrics. These aren't spray-and-pray automated email blasts. They are targeted, high-touch voice interactions designed to trick workers into handing over complete endpoint control.
Initial contact arrives through external Microsoft Teams messages or direct voice calls. Sophos recorded call durations ranging from 90 seconds to over 20 minutes, though most wrapped up within two to two-and-a-half minutes. That brief window gives callers all the time they need to work their script.
Historically, attackers using Teams impersonation created temporary tenants under Microsoft's standard onmicrosoft.com infrastructure. STAC4749 abandoned that pattern completely. Instead, they registered custom IT-themed domains under the generic .top top-level domain. Malicious domains identified during the campaign include sequrityupdate.top, scan-security.top, system-connect.top, corp-connect.top, and supportsoft.top.
The group mapped these domains to fixed aliases:
- Anthony Brooks
- Dylan Harper
- Ethan Parker
- Jason Mitchell
Once on the call, the fake technician convinces the target worker to start a remote support session. Their initial tool of choice was Microsoft Quick Assist—a native Windows feature that users naturally trust. If internal policies blocked Quick Assist, the callers pivoted. Starting in April, attackers increasingly relied on RemSupp, a cloud-based remote management utility far less likely to trigger application blocklists.
After gaining remote access, the attackers launched PowerShell commands to drop a backdoor into the target's %AppData% folder. To keep long-term access without alarming security teams, they created malicious registry keys disguised as legitimate system components. Names like Realtek HD Audio, Realtek Audio UHD, and WinAudio life2 allowed the malware to sit quietly beside actual drivers. To prepare for lateral movement, STAC4749 installed backup tools like DWAgent and AnyDesk while attempting to activate Remote Desktop Protocol (RDP) across local network segments.
From Initial Access to Ransomware in 17 Hours: Chaos Deployment and Group Lineage
The speed of the STAC4749 campaign shows how fast modern extortion operations move. Out of dozens of targeted firms, roughly 95% were based in North America—with Canada absorbing 50% of the hits and the United States taking 45%. The attackers didn't care about industry niches either; they hit services, manufacturing, energy, construction, and engineering firms alike.
In at least three intrusions, initial remote access quickly led to Chaos ransomware deployment. Chaos operates as a ransomware-as-a-service (RaaS) platform active since early 2025. Once inside, the malware encrypts files across accessible network shares, leaving behind ransom notes titled readme.chaos.txt. The notes claim data was stolen prior to encryption and threaten public exposure if ransom demands aren't met.
According to research detailed by BleepingComputer, STAC4749 represents a financially motivated threat team with direct ties to notorious cybercrime syndicates. Sophos analysts assess with high confidence that the operators include former members of the BlackSuit and Royal ransomware gangs, both of which branched off from the Conti syndicate.
This isn't an isolated experiment in chat-based vishing. Back in October 2024, Black Basta affiliates flooded enterprise inboxes before reaching out via Microsoft Teams to "help resolve" the spam overload. State-sponsored groups like MuddyWater have also used Chaos ransomware payloads to cover cyberespionage operations. However, Sophos confirmed no operational link between MuddyWater and STAC4749, confirming STAC4749 remains focused on quick cash extortion.
As we analyzed in our breakdown of human layer security vulnerabilities, identity and social engineering remain the primary attack vectors for modern extortion cartels. When human trust breaks down, perimeter firewalls can't save you.
Securing Corporate Systems: IBM Insights, CISA Security Practices, and Defenses
Defending against Teams-based vishing takes more than telling staff not to click links. It requires tight identity boundaries, strong application controls, and practical defensive training. IBM security research consistently shows that initial access gained through social engineering remains among the most costly breach vectors for modern organizations.
First, lock down external Microsoft Teams communications. By default, Teams allows external domain federation, letting outside users contact your staff unless admins intervene. Organizations should enforce strict domain allowlists or turn off external communications for general employees. If external chat is required, add clear UI banners that flag incoming calls from outside tenants and highlight risky domain extensions like .top.
Second, enforce application controls over Remote Monitoring and Management (RMM) tools. Microsoft Quick Assist, RemSupp, AnyDesk, and DWAgent must be tightly restricted. If employees need tech support, they should request it through an internal, authenticated portal—never from an incoming call. Restricting unapproved remote management agents stops attackers from building a foothold even if a user falls for the pitch.
Third, align corporate defenses with CISA security practices. As highlighted in CISA guidance on critical infrastructure resilience, segmenting operational networks from standard corporate networks limits lateral movement. EDR agents should alert on PowerShell scripts spawning from %AppData% and registry edits mimicking sound drivers.
Finally, run regular tutorial simulation exercises for internal helpdesk workflows. Staff must know that real IT team members will never ask them to disable security software, install third-party support software from .top domains, or enable RDP over an unverified voice chat.
As automated threat toolkits and agentic AI security frameworks evolve, cybercriminals will double down on direct communication channels. Implementing complete defense-in-depth controls across identity, chat applications, and endpoints is the only way to keep a two-minute support call from locking down your entire network.