Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmed

STAC4749 Teams vishing campaign led to Chaos ransomware in North America

Dozens of North American organisations (unnamed) · Manufacturing · Canada · February 2026

What happened

Sophos tracked a campaign designated STAC4749 that ran from February through June 2026 and targeted dozens of North American organisations, roughly 50 percent in Canada and 45 percent in the United States. Sectors hit included services, manufacturing, energy and construction/engineering. At least three compromises escalated to Chaos ransomware deployment, one of them going from first contact to file encryption in under 17 hours.

How the deception worked

The operators registered IT-themed domains under the .top extension and created fake support personas with names such as Anthony Brooks and Dylan Harper. They contacted employees through Microsoft Teams, posed as internal IT support, and asked for a remote session using Microsoft Quick Assist or RemSupp. Once a user granted control, the attackers ran PowerShell to install a backdoor, established persistence through disguised registry entries, and deployed further remote access tools such as DWAgent or AnyDesk for lateral movement before staging Chaos ransomware.

AI involvement · Unknown

Sophos described fake identities and IT-themed domains but did not report AI-generated voice or video.

The control that would have caught it· our reading, not a claim from the sources

Restricting Microsoft Teams messages from external tenants, and blocking or tightly controlling Quick Assist, closes the channel this campaign depended on.

Sources (1)

  1. Microsoft Teams vishing attacks lead to Chaos ransomware attacks
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.