Published on 31 July 2026
A two-minute call over Microsoft Teams – that's all it takes to encrypt an entire corporate network. What looks like a harmless contact from IT support ends, in documented cases, in complete ransomware encryption – in one case in less than 17 hours after the initial contact. The security firm Sophos has uncovered a systematic attack campaign dubbed STAC4749, in which criminals pose as an IT help desk, persuade employees to grant remote access, and then deploy the so-called Chaos ransomware. We explain what happened, whether you could be affected, and what specific steps you need to take now.
Between February and June 2026, Sophos documented dozens of attacks on organisations – predominantly in North America. The attackers did not exploit a technical vulnerability in Microsoft Teams, but rather people as the weak point. Specifically, they posed as IT support staff in Teams chats and voice calls and convinced employees to grant them remote access to their work computers.
This method is known as vishing – a combination of "voice" and "phishing", i.e. tricking someone into granting access via telephone or voice call. Most of the observed calls lasted only two to two and a half minutes. That was enough to get the victim to grant access.
In at least three documented cases, the attack led to complete encryption by the Chaos ransomware – extortion software rented out as "ransomware-as-a-service", meaning it can be used by criminals for a fee. Sophos links the campaign with high confidence to former members of the notorious ransomware groups BlackSuit, Royal and Conti – highly professional, experienced perpetrators.
"Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either deployed ransomware directly or coordinated with affiliates." – Morgan Demboski, Sophos X-Ops
The attack proceeds in several phases that build on one another. Explained clearly, it looks like this:
The attackers register their own Microsoft 365 accounts under IT-themed internet addresses ending in .top – such as sequrityupdate[.]top, scan-security[.]top or system-connect[.]top. Unlike earlier campaigns that used fake onmicrosoft.com addresses, these custom domains appear more legitimate at first glance. They are combined with credible English-language names such as "Anthony Brooks" or "Ethan Parker".
The victim is persuaded to launch a legitimate remote maintenance tool – until April 2026 preferably Microsoft Quick Assist (a remote help tool built into Windows), and after that increasingly the cloud-based tool RemSupp. The switch was likely made because RemSupp appears less often on companies' block lists.
Once the attackers have remote access, they use PowerShell (a powerful Windows command-line tool) to download a Python-based backdoor. This usually lands in the user directory %AppData%\Roaming. To stay undetected, the attackers disguise their autostart entries as harmless audio components with names such as "Realtek HD Audio Universal Service" or "WinAudio life2".
In cases that led to ransomware, the attackers additionally installed DWAgent or AnyDesk as backup access routes and enabled the Remote Desktop Protocol (RDP) to move laterally through the network. Finally, the Chaos ransomware was rolled out almost simultaneously across all compromised devices. The ransom demand lands in a file named readme.chaos.txt and additionally claims that data has been stolen.
Around 95 percent of the attacks targeted companies in Canada (50%) and the USA (44%). Affected sectors were services (20%), manufacturing (17%), energy (12%) as well as construction and engineering (12%). Notably: all law firms that were attacked specialised in intellectual property.
Even though the focus is on North America, there is no reason for German companies to relax. Microsoft Teams is widely used in companies of every size, and the external communication feature is enabled by default. The attack model can be applied anywhere geographically. According to the ENISA Threat Landscape 2025, Germany, with 23.4 percent of all EU ransomware victims, is the most heavily affected country in the EU – and 90 percent of ransomware attacks in Germany target small and medium-sized enterprises (BKA situation report 2025).
Since no software vulnerability is being exploited here, there is no patch. Protection starts with your employees and your configuration. The following steps are ordered by urgency.
Immediately disconnect affected devices from the network, secure evidence (Teams logs, PowerShell logs, registry snapshots), reset passwords and inform your IT security service provider as well as, where applicable, the relevant data protection authority.
A successful STAC4749 attack has considerable data protection consequences. Since the attackers steal data before encryption ("double extortion"), there is generally a reportable data breach.
The risk this campaign poses to German SMEs must be classified as high. The barrier to entry for attackers is minimal – no exploit, just a convincing call. The attack vector is ubiquitous because Teams is used everywhere. And the time window is brutally short: without continuous monitoring, SMEs have little chance to respond.
"STAC4749 is a reminder that modern ransomware defence begins before the malware is executed. The decisive moment may be when an employee receives a Teams call, sees a legitimate Windows tool and is persuaded to grant an unknown stranger access." – WindowsForum Security Analysis
The economic consequences are dramatic: according to Exabeam, 60 percent of small companies have to close within six months of a ransomware attack. In Germany, a total of 1,041 ransomware attacks were reported in 2025 – an increase of 10 percent over the previous year. The total damage caused by cyberattacks amounted to 202.4 billion euros.
STAC4749 is a case study in the fact that the most dangerous vulnerability often lies not in the software, but in a trusting "yes" at the other end of a Teams call. No virus scanner, no patch and no firewall protects you if an employee voluntarily opens the door. The good news: precisely for that reason, the most effective protection lies in your hands. Restrict external Teams communication, block unauthorised remote maintenance tools, enable MFA – and above all: train your employees. A single clear principle is often enough to nip the attack in the bud: Genuine IT support never calls unsolicited and demands remote access. Anyone who embeds this sentence in their team has already taken the decisive step.