Vishing via Microsoft Teams: STAC4749 Spreads Chaos Ransomware

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/6 · Initial Access via Social Engineering

Attackers impersonate the IT helpdesk in Microsoft Teams chats and voice calls to gain the victim's trust.

T1566 – Phishing T1656 – Impersonation T1585 – Establish Accounts
  • Vishing calls lasting only 2–2.5 minutes
  • Own M365 accounts on .top domains (sequrityupdate[.]top, scan-security[.]top)
  • Credible names like 'Anthony Brooks' or 'Ethan Parker'
  • Abuses externally-enabled Teams communication (on by default)
PHASE 2/6 · Remote Access via Legitimate Tools

The victim is convinced to launch a legitimate remote support tool and grant access.

T1219 – Remote Access Software T1204 – User Execution
  • Microsoft Quick Assist preferred until April 2026
  • Then increasingly cloud-based RemSupp (less often blocklisted)
  • Under 17 hours from first contact to encryption
PHASE 3/6 · Malware Execution

PowerShell is used to download and run a Python-based backdoor.

T1059.001 – Command and Scripting Interpreter: PowerShell T1105 – Ingress Tool Transfer T1059.006 – Command and Scripting Interpreter: Python
  • Backdoor typically dropped in %AppData%\Roaming
  • Payload filenames changed repeatedly (sekv…, helper…, 74fs…)
  • From April 2026 direct deployment instead of separate loader
PHASE 4/6 · Persistence and Evasion

Autostart entries are disguised as harmless audio components to evade detection.

T1547.001 – Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1036 – Masquerading
  • Disguised names: 'Realtek HD Audio Universal Service', 'WinAudio life2'
  • Persistence via HKCU\...\CurrentVersion\Run
  • Shortcuts/VBScript in the Startup folder
PHASE 5/6 · Lateral Movement

Backup access channels are installed and RDP is enabled to spread across the network.

T1021.001 – Remote Services: Remote Desktop Protocol T1219 – Remote Access Software
  • Deployment of DWAgent or AnyDesk as fallback access
  • Enabling the Remote Desktop Protocol (RDP)
  • Preparing the simultaneous ransomware rollout
PHASE 6/6 · Encryption and Extortion

Chaos ransomware is deployed almost simultaneously across all compromised devices.

T1486 – Data Encrypted for Impact T1657 – Financial Theft
  • Chaos ransomware operated as Ransomware-as-a-Service
  • Ransom note in 'readme.chaos.txt', also claims data theft
  • Linked with high confidence to ex-BlackSuit/Royal/Conti members
  • Dozens of attacks (Feb–Jun 2026), 95% against Canada/USA
Short & clear answers
Frequently asked questions about this incident
Am I affected by this Microsoft Teams attack?
Any organization using Microsoft Teams with external communication enabled is potentially at risk – this feature is on by default. The attack does not exploit a software flaw but deceives employees by impersonating IT support. Check in the Teams Admin Center whether external communication with arbitrary domains is allowed, and ask staff whether they received unsolicited Teams calls from external IT support.
How do I know if my network has already been compromised?
Look for suspicious autostart entries under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, especially ones disguised as audio components like 'Realtek HD Audio Universal Service' or 'WinAudio life2'. Check for unknown executables in %AppData%\Roaming and for unauthorized remote tools such as AnyDesk, DWAgent, or RemSupp. A clear red flag is a ransom note in a file named readme.chaos.txt.
What should I do right now?
Make it crystal clear to your staff that legitimate IT support never requests remote access via an unsolicited Teams call – such contacts must be declined and reported. Establish that remote support is only ever requested through the official helpdesk portal or a known internal phone number. Since no software vulnerability is exploited, there is no patch – protection starts with people and configuration.
Is there a patch or update to fix this attack?
No. The attack does not exploit a technical vulnerability in Microsoft Teams but relies on social engineering (vishing), tricking employees into granting remote access. That's why no software update helps; effective measures are restricting external Teams communication (allowlist), blocking unauthorized remote tools, enabling MFA, and training employees.
Is my German business even at risk if the attacks happened in North America?
Yes. About 95% of documented attacks hit Canada and the USA, but the attack model is geographically transferable. Microsoft Teams is used by companies of every size, and external communication is enabled by default. According to ENISA, Germany is the EU country most affected by ransomware, and 90% of those attacks target small and medium-sized businesses.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.