Teams vishing to ransomware in 17 hours: lock external chat
Sophos tracked a Microsoft Teams vishing campaign against dozens of North American firms. Fake IT helpdesk calls, then Chaos ransomware. Restrict external Teams access.
Sophos published its analysis of STAC4749 on July 30: a Microsoft Teams vishing campaign that hit dozens of organizations between February and June 2026, ending in Chaos ransomware at least three times. In one case, initial access to encrypted files took under 17 hours. No exploit, no CVE, no patch to apply. Somebody called an employee on Teams, said they were IT, and the employee said yes.
What actually happened
Per Sophos, the attackers worked from external Teams accounts, opening with chats and voice calls while impersonating helpdesk or IT support. Roughly 94% of targets were in Canada (50%) and the US (44%). The industry spread reads like a normal customer list: services 20%, manufacturing 17%, energy 12%, construction and engineering 12%, plus law firms doing IP work.
The chain after the call is mundane, which is the point. Victims were talked into a remote support session — Microsoft Quick Assist early in the campaign, an RMM tool called RemSupp from April onward. From there: PowerShell pulling custom loaders and Python backdoors, persistence via registry Run keys disguised as audio drivers, then Golang implants, DWAgent, AnyDesk, and a custom SOCKS proxy for backup access. When the ransomware fired, encryption hit endpoints nearly simultaneously.
Note what carried the attack: two tools your IT provider legitimately uses, and a Teams call from outside your tenant.
Why Teams vishing matters for your business
Your security spend assumes attacks arrive as email. This one arrives as a chat from a person with a plausible name, inside the app your staff already trust, and it beats every filter you're paying for.
Three controls, none of which need a new vendor. First, open the Teams admin center and look at external access. Most small businesses do not need open federation with every Microsoft tenant on earth — restrict it to an allowlist of domains you actually work with, and shut off unmanaged-account chat. That single setting removes the entry point. Second, put a rule in writing and say it out loud in a staff meeting: IT never initiates a remote session over Teams. Give people one phone number to call back on, and make "I'll verify and call you" a response nobody gets in trouble for. Third, decide whether Quick Assist should run on your machines at all. If your provider uses a different tool, block it.
Then check the boring one. The 17-hour case ended in simultaneous encryption across endpoints — the difference between a bad week and a closed business is whether your backups are offline, restorable, and tested this quarter. Not configured. Tested.
Key takeaways
- Sophos tracked STAC4749 hitting dozens of orgs Feb–June 2026; ~94% in Canada and the US, across services, manufacturing, energy, and construction
- Entry was external Teams chats and calls impersonating IT helpdesk — no exploit, no vulnerability to patch
- Attackers used Microsoft Quick Assist, then the RemSupp RMM, followed by PowerShell loaders, Python backdoors, and Run-key persistence
- At least three intrusions ended in Chaos ransomware; one ran from access to encryption in under 17 hours
- Operator moves: restrict Teams external access to an allowlist, ban IT-initiated remote sessions over chat, and test your offline backups
The gap isn't your firewall, it's your front door. We tighten Microsoft 365 and Teams tenant settings, cut external access down to domains you actually work with, and write the verification rule your team will follow at 4pm on a Friday. See how we harden your stack or have us review your tenant.
Sources: Sophos, BleepingComputer.
- #microsoft-teams
- #ransomware
- #social-engineering
- #security
- #msp
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Cyera's $1B Oasis deal: agent identity tools consolidate
Cyera signed a letter of intent to buy Oasis Security for about $1B, mostly cash. AI agent identity is consolidating — keep the controls in your own stack.
Read itCentralize's $19M: your relationship data is the product
Centralize raised $15M led by NEA to map deals from your email, calendar, CRM, and call recordings. Scope what you connect before you connect it.
Read it