A new vishing campaign is targeting Microsoft Teams – here's what users need to know

Researchers warn Microsoft Teams users across North America are in the crosshairs

Logo and branding of Microsoft Teams application pictured on a smartphone screen, with blue and purple colors flashing in background.
(Image credit: Getty Images)

Sophos has uncovered a Microsoft Teams voice phishing (vishing) campaign targeting dozens of organizations between February and June this year.

Attackers impersonated IT support staff to gain remote access to victim systems and deploy Chaos ransomware – in one case, less than 17 hours after the initial compromise.

Tracked as STAC474, the campaign was overwhelmingly aimed at North America, with 50% of targeted organizations based in Canada and 44% in the US.

In terms of sectors, there was a broad distribution, with services organizations impacted in 20% of the incidents, followed by manufacturing, energy, and construction and engineering, as well as law.

Latest Videos FromIT Pro

Notably, Sophos said legal organizations targeted in the campaign specialize in intellectual property (IP) law or services.

How the Microsoft Teams attacks work

First contact comes via Teams chats and calls, impersonating helpdesk or IT support staff.

Unlike earlier Teams abuse campaigns in which attackers spoofed onmicrosoft[.]com tenants, Sophos noted that STAC4749 operators created IT-themed cloud domains under the “.top” top-level domain (TLD) and leveraged plausible employee usernames to make the accounts appear legitimate.

The aim was to launch a remote session through an existing tool or by downloading an alternative. Through this, the operators launched PowerShell on the compromised system to retrieve and execute malicious payloads hosted on attacker‑controlled web servers.

These payloads were typically staged in user‑writable directories, most commonly AppData\Roaming.

The first-stage payload collected system identifiers such as the computer name, machine GUID, and operating system version, and queried registry keys under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion to fingerprint the host.

It also attempted to discover security products that were active on the system, according to researchers.

Shortly after the discovery phase, the first-stage payload created a new registry Run key to enable persistence at user logon. After establishing persistence, the Python-based backdoor connected to a C2 server and retrieved Golang-based implants that were executed via a PowerShell Invoke-WebRequest command.

"At least three STAC4749 compromises led to Chaos ransomware deployment. In these incidents, the ransomware was deployed shortly after the attackers expanded access across multiple systems and, in at least one instance, likely exfiltrated data," said Sophos threat intelligence analyst Morgan Demboski.

"Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates."

What is Chaos ransomware?

The Chaos Ransomware as a Service (RaaS) operation has been active since at least February 2025.

Rapid7 recently suggested that it could be a false flag by the Iranian threat group known as MuddyWater.

However, Sophos said it has no evidence of this, reckoning instead that it has a Russian-language connection.

How to stay secure

Sophos outlined a series of recommendations for organizations at risk, including:

  • Monitoring Teams activity for suspicious external messages and voice calls
  • Implementing endpoint detection and response (EDR) capabilities
  • Regularly reviewing registry Run keys and other common persistence locations

Organizations should also carry out user awareness training, enforce application control policies and restrict unauthorized software execution.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Emma Woollacott

Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.