Vishing Attacks via Microsoft Teams Lead to Chaos Ransomware – Veri Sızıntısı

Microsoft Teams Calls Launch Chaos Ransomware Attacks

Cyberattackers, posing as IT support staff, are infiltrating corporate networks through voice calls on Microsoft Teams and deploying Chaos ransomware. The campaign, tracked by Sophos as STAC4749, primarily targets organizations in North America.

A phone handset and a lock icon superimposed over the Microsoft Teams logo

What Happened

Cybersecurity firm Sophos has revealed that the corporate communication platform Microsoft Teams is at the center of a new and alarming attack chain. In this campaign, dubbed STAC4749, cyberattackers impersonate a company's IT support or help desk staff. They establish trust with targeted employees through both chat and voice calls on Microsoft Teams, and then deploy the Chaos ransomware, which threatens the entire corporate network. This sophisticated social engineering campaign, conducted between February and June 2026, targeted dozens of organizations.

According to the analysis, at least three of these attacks resulted in the attackers achieving their ultimate goal of successfully deploying the Chaos ransomware. In one particularly notable case, the attackers went from gaining initial access to encrypting files on the network in less than 17 hours, demonstrating how quickly and devastatingly the attack can unfold. This method goes beyond traditional phishing emails, leveraging a platform that is an integral part of employees' daily workflow and is generally considered secure. The attackers call these attacks, conducted using Teams' voice call feature, 'vishing' (voice phishing), which enhances their ability to persuade and manipulate their targets more easily.

Data Compromised

The source report does not provide specific information on whether the attackers exfiltrated data. The primary objective of the attack appears to be deploying the Chaos ransomware to render files inaccessible and demand a ransom in return. In ransomware attacks, it is a common tactic to steal sensitive data in addition to encrypting files (a double-extortion tactic) to pressure the victim. However, the Sophos report does not focus on this stage of the STAC4749 campaign. The primary impact of the attack is stated to be operational disruptions and potential financial losses due to encrypted files.

How Did the Attack Unfold

The path followed by the attackers consists of several carefully planned stages. This chain becomes highly effective by combining social engineering, which targets human psychology, with technical skill.

Stage 1: Impersonation and Initial Contact

The attackers begin by creating external Microsoft Teams accounts. They make these accounts appear as if they belong to an employee from the target company's IT help desk or support team. While in similar past attacks attackers often used Microsoft's own `onmicrosoft.com` domain to create fake tenants, the STAC4749 campaign differs at this point. To appear more convincing, the attackers purchase custom domains with the '.top' TLD that seem IT-related. Example domains shared by Sophos include sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, corp-connect[.]top, and supportsoft[.]top. These domain names give the impression of a corporate security update or support service, preventing the target from becoming suspicious.

Furthermore, to strengthen these fake identities, they use common and trustworthy-sounding names like Anthony Brooks, Dylan Harper, Ethan Parker, and Jason Mitchell. It was observed that each fake identity was paired with a specific fake domain. After these preparations, they send a chat request to their chosen target employee via Teams and then initiate a voice call.

Stage 2: Vishing and Remote Access

The voice call (vishing) is the most critical moment of the attack. According to Sophos's observations, these calls can last from 90 seconds to over 20 minutes, but most are completed in an average of two to two-and-a-half minutes. This short duration indicates that the attackers are well-prepared, confident, and persuasive. During the call, the fake IT personnel claim there is an urgent security issue on the employee's computer or that an update needs to be performed, convincing them to start a remote support session.

For this purpose, they initially prefer to use Microsoft's legitimate remote assistance tool, Quick Assist. However, upon realizing that many companies block or restrict Quick Assist due to security policies, they change their strategy. Starting in April, they switch to a lesser-known, cloud-based remote management tool called RemSupp, which is less likely to be on corporate blocklists. When the employee installs one of these tools and grants access to the attacker, the attackers gain full control over the victim's device.

Stage 3: Malware Download and Persistence

Once remote access is established, the attackers use the command-line tool PowerShell to download a backdoor malware into the victim's `%AppData%` folder. This malware profiles the system, establishes persistence mechanisms, and provides the attackers with continuous access to the network.

To avoid detection, the attackers disguise the persistence mechanisms they set up as legitimate system components. For example, they give the malicious entries they create in the Windows Registry names like "Realtek HD Audio", "Realtek Audio UHD", and "WinAudio life2", creating the impression that they are standard components belonging to audio drivers.

Stage 4: Lateral Movement and Ransomware Deployment

In cases that resulted in ransomware deployment, the attackers take additional steps to spread from the initially compromised device to the rest of the network. To maintain persistent and redundant access within the network, they install additional remote access tools like DWAgent or AnyDesk. They also attempt to enable the Remote Desktop Protocol (RDP) on compromised devices to move laterally to other systems. This lateral movement capability means that a single employee's mistake can endanger the data of the entire company. In the final stage, once they have sufficient access across the network, they deploy the Chaos ransomware and encrypt files.

Who Was Affected

According to the Sophos report, the campaign is geographically focused heavily on North America. Approximately 95% of the attacks target organizations in this region. Of this percentage, 50% are companies in Canada, and 45% are in the United States. The sectors targeted by the attackers are quite diverse. The most attacked sectors include services, manufacturing, energy, and construction and engineering. This diversity shows that the attackers are not focused on a specific industry but will target any organization with a weak security link.

What Can You Do

Protecting against these types of social engineering-focused attacks requires both technical measures and employee awareness:

  • Employee Training: Warn employees about unexpected Microsoft Teams messages and calls, especially from external accounts. Emphasize that legitimate IT support staff will never initiate contact this way or ask for personal information or remote access.
  • Verification Procedures: Instill a habit of verifying any request allegedly from the IT department through a known and official channel (e.g., the company's internal phone number or support portal).
  • Application Control: Restrict the use of remote access tools like Microsoft Quick Assist, RemSupp, and AnyDesk. If not necessary, add these applications to corporate application blocklists.
  • PowerShell Monitoring: Monitor and restrict PowerShell usage. Create alert mechanisms for PowerShell activities, especially those that download files from the internet or run suspicious commands.
  • Monitor Persistence Points: Be prepared for the methods used by attackers. Regularly audit suspicious Registry entries, especially those disguised as audio drivers.

What the Company Is Saying

The news is based on the analysis and report from the cybersecurity company Sophos. Sophos states that the threat actor it tracks as STAC4749 continuously changed its attack chain and improved its methods between February and May. This indicates that the attackers are dynamic and adaptable. The source article does not include a statement from Microsoft regarding the Microsoft Teams platform, which was targeted in the attacks.

Source

https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.