Fake IT support calls on Microsoft Teams are ending in ransomware

Attackers are calling employees on Microsoft Teams, posing as the company IT helpdesk, and talking them into opening a remote support session. In at least three cases documented by Sophos, that call ended with Chaos ransomware encrypting the network less than a day later.

Sophos analysts track the campaign as STAC4749 and watched it hit dozens of North American organizations between February and June 2026. Nearly 95 percent of the victims sat in Canada (50 percent) and the United States (44 percent). Services firms accounted for 20 percent of incidents, followed by manufacturing (17 percent), energy (12 percent), and construction and engineering (12 percent). Notably, every legal organization caught in the campaign specialized in intellectual property work.

How the attack works

The operators open a Teams chat or voice call while impersonating helpdesk or IT support staff. Most calls ran two to two and a half minutes, though analysts saw some stretch past 20 minutes. Rather than spoofing onmicrosoft[.]com tenants, as earlier Teams campaigns did, this crew registered IT themed domains on the .top top level domain (sequrityupdate[.]top, scan-security[.]top, corp-connect[.]top) and paired them with plausible staff names such as AnthonyBrooks and DylanHarper to make the accounts look real.

The point of the call is to start a remote session. Operators initially steered victims toward Microsoft Quick Assist and fell back to the cloud based RemSupp remote management tool when Quick Assist was blocked. Since April they have preferred RemSupp, which Sophos assesses is less likely to sit on an application blocklist. Once connected, they enable Remote Desktop on the first machine to reach others.

PowerShell then pulls the real payload into the user AppData folder: a loader that fingerprints the host, adds a registry startup key disguised as a Realtek audio component, and fetches a Python backdoor. That backdoor retrieves Go based implants which only talk to servers presenting a matching pinned certificate, issued by authorities named loop-CA, connectify-CA and james-bond-CA. That trick keeps each set of payloads locked to its own infrastructure and frustrates researchers trying to connect the dots.

A second vendor sees the same playbook

A day before the Sophos write up, Zscaler ThreatLabz published research on an initial access broker it has tracked since January 2026 running the same opening move: Teams vishing into a Quick Assist session. That crew deploys a Go backdoor ThreatLabz named GoGRPC, in four evolving variants, alongside a data theft tool called S3Siphon that quietly uploads Desktop, Documents and Downloads files to an attacker controlled cloud bucket, almost certainly to fuel extortion.

Neither vendor explicitly links the two clusters, but the published artifacts overlap closely. Both describe a PowerShell one liner dropping a file named sekv followed by random digits into AppData, both list a startup key named after Realtek audio, and both mention an appscreen.log file written under ProgramData.

Who is behind it

Chaos is a ransomware as a service operation active since at least February 2025, reportedly started by former members of the BlackSuit (Royal) crew. Sophos assesses with high confidence that STAC4749 was financially motivated and either deployed ransomware itself or worked with affiliates. On attribution the team is deliberately cautious: it found no evidence supporting an earlier suggestion that Chaos is a false flag for an Iranian group, and while one operator mistyped a Russian keyboard version of the "dir" command, Sophos says there is not enough evidence to name anyone. We covered a separate strand of this crew earlier this month when Chaos began hiding its traffic inside the browser.

What you should do

Treat unexpected Teams contact from outside your tenant as hostile until proven otherwise, and give staff a simple rule: no legitimate helpdesk will cold call and ask you to launch a remote support tool. Block or restrict Quick Assist and unapproved remote management software, alert on PowerShell downloading executables into AppData, and audit registry startup keys for entries impersonating audio drivers. This is the same social engineering shift we flagged when attackers began phishing through Teams rather than email.

Selected indicators (defanged): 94[.]140[.]114[.]192, 94[.]140[.]115[.]18, 94[.]140[.]115[.]129, 193[.]29[.]57[.]37, and the payload host fa5[.]flsdwnld[.]online. Full detail is in the original report by Sophos threat intelligence analyst Morgan Demboski.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions