Microsoft Teams Is Now a Ransomware Entry Point: STAC4749 Deploys Chaos in Under 17 Hours
Your organisation’s Microsoft Teams workspace is open right now. An employee just answered what looked like a routine IT support call. Seventeen hours later, every file on your network is encrypted and a ransom note is waiting on every desktop. This is not a hypothetical — it is exactly how STAC4749, a financially motivated threat cluster tracked by Sophos, operated throughout the first half of 2026, targeting dozens of North American enterprises using little more than a fake Teams account and a two-minute conversation.
- Sophos tracked campaign STAC4749 from February to June 2026, with confirmed ransomware deployment in at least three organisations.
- Attackers posed as IT helpdesk staff using external Microsoft Teams accounts on convincing .top domains — no email phishing required.
- The average call lasted just 90 seconds to two minutes before victims handed over remote access via Quick Assist or RemSupp.
- Time from first Teams contact to full Chaos ransomware deployment: under 17 hours in the fastest recorded incident.
- The group is assessed to include former members of the BlackSuit, Royal, and Conti cybercrime syndicates.
- Defences must address the human layer — user awareness, Teams external-access controls, and rapid endpoint detection.
The Anatomy of a Two-Minute Catastrophe
STAC4749 relied on a brilliantly simple premise: most employees assume that anyone who reaches them inside Microsoft Teams is a legitimate colleague or authorised vendor. The attackers exploited Microsoft’s default configuration that permits external users to initiate chats and calls with internal staff.
The threat actors created Teams accounts on .top-TLD domains designed to mimic corporate IT departments — names such as sequrityupdate[.]top, scan-security[.]top, system-connect[.]top, and service-help[.]top. They paired these domains with plausible Western IT-support personas: AnthonyBrooks, DylanHarper, EthanParker, EllaBrooks. To a busy employee receiving an unexpected Teams call from “Dylan Harper — IT Support,” nothing immediately raises an alarm.
The conversation itself was short. The “technician” explained there was an urgent security issue on the employee’s workstation and requested permission to log in remotely using Microsoft Quick Assist — a built-in Windows tool — or the third-party RemSupp remote monitoring application. Most employees complied within minutes. Three incidents escalated to full network encryption in under 17 hours from that first call.
Under the Hood: A Modular, Layered Attack Chain
Once inside, STAC4749 operators moved with practised efficiency. Sophos researchers documented a modular toolset designed for stealth and resilience:
| Stage | Tool / Technique | Purpose |
|---|---|---|
| Initial Access | Quick Assist / RemSupp | Remote desktop session via social engineering |
| Persistence | DWAgent, AnyDesk | Backup remote access; RDP enablement |
| Disguise | Realtek HD Audio / WinAudio life2 | Backdoor payloads disguised as audio drivers |
| C2 Comms | Python loader → Golang implants | Custom CA-pinned encrypted C2 channels |
| Discovery | Built-in Windows commands | Network mapping, credential harvesting |
| Impact | Chaos Ransomware | Simultaneous encryption + data exfiltration claim |
One particularly notable tactic was the use of certificate pinning with custom certificate authorities — named with identifiers such as loop-CA, connectify-CA, and james-bond-CA. By embedding these custom root certificates into the Golang implants, the operators segmented their infrastructure so that even if one C2 node was burned, the remaining implants kept communicating on separate, pinned channels. This is a level of operational security more commonly associated with nation-state actors than ransomware crews.
The backdoors were disguised as legitimate audio software — a classic living-off-the-land technique that exploits IT teams’ tendency to trust processes bearing familiar driver names. By the time any suspicious process was flagged, the operators had often already established multiple persistent access paths.
Who Is STAC4749?
Sophos assesses with high confidence that STAC4749 is a financially motivated operation with structural ties to the Conti cybercrime syndicate’s successor groups — specifically former members of the BlackSuit and Royal ransomware gangs. Both Royal and BlackSuit were themselves rebrands of the now-defunct Conti operation, which was one of the most prolific ransomware groups in history before its internal communications were leaked in 2022.
The campaign ran from February to June 2026, targeting organisations primarily in Canada (50%) and the United States (45%). The hardest-hit sectors were:
- Services (20% of victims)
- Manufacturing (17%)
- Energy (12%)
- Construction and Engineering (12%)
- Intellectual property law firms were specifically singled out — likely for the value of confidential client data
While the current data concentrates in North America, the STAC4749 playbook requires nothing geography-specific. Microsoft Teams is used by millions of organisations across India and the Asia-Pacific region — in financial services, IT/ITeS, manufacturing, and government — and default Teams external-access settings create identical exposure everywhere. Ransomware affiliates routinely pivot to new geographies once a playbook is refined, and there is no reason Indian enterprises should consider themselves safe.
Why Vishing Through Teams Is So Effective
Traditional phishing awareness training teaches employees to scrutinise email sender addresses and avoid clicking links. Vishing through Microsoft Teams bypasses all of that mental model. Here is why this attack vector is so effective:
- Platform trust halo: Employees perceive Teams as a controlled corporate environment. An unexpected email from an unknown sender triggers suspicion; an unexpected Teams call does not, because people assume it passed through IT security controls.
- Urgency is built in: A live voice call creates instant social pressure. The “technician” can answer questions in real time, adapt to objections, and project authority — far more powerful than a phishing email.
- Built-in remote-access tools: Quick Assist ships with Windows 10/11. Asking employees to use it sounds like normal IT practice.
- No malicious attachment: The initial intrusion leaves almost no phishing artefacts. There is nothing for email security gateways or URL filters to block.
What You Should Do Right Now
As a cybersecurity consultant who has spent three decades advising enterprises on zero-trust architecture and perimeter defence, Sanjay Seth‘s assessment is direct: this attack does not require a sophisticated technical vulnerability — it exploits the gap between your security policy and what your employees actually do under social pressure. Fixing it requires layered controls.
Immediate Actions (This Week)
- Restrict Teams external access. In the Microsoft Teams Admin Centre, navigate to Users → External Access and disable or allowlist-only external Teams communication. Most organisations have no legitimate need to receive cold-call Teams requests from unknown external domains.
- Block Quick Assist deployment via policy. Unless your IT team explicitly uses Quick Assist, block it via Group Policy or Intune. The same applies to unapproved RMM tools like RemSupp and AnyDesk.
- Issue an all-staff communication today. Tell employees that your IT helpdesk will never initiate unsolicited Teams calls requesting remote access. Provide a callback number they can use to verify any IT contact.
- Audit DWAgent and AnyDesk installs. Scan endpoints for unauthorised RMM tools — these are persistent access mechanisms that survive reboots and user re-authentication.
Medium-Term Controls (30–90 Days)
- Deploy a zero-trust network access (ZTNA) policy so that even if an attacker gains endpoint access, lateral movement requires re-authentication at every network segment boundary. See how ransomware actors exploit trusted access in manufacturing environments.
- Enable Conditional Access for Teams. Require compliant, managed devices for any Teams session involving screen sharing or remote-control tools.
- Tune your EDR/NDR for RMM tool abuse. Quick Assist, RemSupp, DWAgent, and AnyDesk are frequently abused for initial access. Set high-confidence alerts for their installation or execution outside of approved asset-management groups.
- Run a purple-team exercise simulating STAC4749 TTPs against your SOC — specifically the Quick Assist chain. If your blue team cannot detect a fake IT helpdesk call plus Quick Assist session within 30 minutes, your detection posture needs work.
- Implement call-back verification (vishing MFA). Any IT support interaction that results in remote access must be validated by the employee calling back an IT number listed in your intranet — not a number provided by the caller.
For organisations running Cisco or Fortinet perimeter security, ZTNA segmentation combined with micro-segmentation of internal workstations dramatically reduces the blast radius if an attacker does gain initial endpoint access through social engineering. The goal is to ensure that a helpdesk-impersonation call on one employee’s workstation cannot cascade into domain-wide ransomware in 17 hours.
Frequently Asked Questions
Can Microsoft do anything to prevent this kind of attack?
Microsoft can — and organisations should pressure them to — change default Teams configuration so that external users cannot initiate voice calls with internal employees without an explicit admin opt-in. In May 2026 Microsoft began adding caller-authenticity banners for external Teams callers, but these are advisory warnings, not controls. The real fix is administrative policy change in your own tenant.
How is this different from traditional BEC (Business Email Compromise)?
BEC attacks impersonate trusted parties via email. STAC4749 moves the impersonation to a real-time voice channel, which is psychologically far more persuasive. The attacker can respond to scepticism, answer technical questions, and create time pressure in ways that a static email cannot. Voice-based social engineering is also underrepresented in most security-awareness training programmes, making employees less prepared for it.
Is Chaos ransomware particularly dangerous?
Chaos ransomware is a builder-model malware that is sold or leased to affiliates, meaning multiple independent groups can deploy it. The encryption is strong enough to be practically unrecoverable without either a working backup or the decryption key. What makes STAC4749’s use of Chaos notable is the speed and simultaneity of the deployment — hitting all endpoints at once to maximise impact before defenders can respond.
Does this affect Indian enterprises specifically?
STAC4749’s documented targets were North American, but the attack method is entirely geography-agnostic. Teams is deeply embedded in India’s IT/ITeS, BFSI, and manufacturing sectors. The social engineering premise — a polite IT support call — may actually be more effective in cultures with strong deference to authority figures such as IT staff. Indian CISOs should treat this as an immediate relevant threat, not a distant Western problem.
Protect Your Organisation Before the Call Comes
The STAC4749 campaign is a reminder that the most dangerous cybersecurity vulnerabilities are not always in software — sometimes they are in the gap between your written security policy and your employees’ real-world behaviour under social pressure. A Conti-lineage ransomware affiliate needed no CVE, no zero-day, and no phishing email. They needed a Teams account, a plausible name, and two minutes of your employee’s time.
Closing that gap requires a combination of technical controls (Teams external-access restrictions, RMM tool blocking, ZTNA segmentation) and human controls (targeted awareness training, callback verification procedures, and a culture where questioning an unsolicited IT call is encouraged, not embarrassing).
If you want a professional assessment of your organisation’s exposure to vishing, social engineering, and ransomware attack paths — including a review of your Microsoft Teams configuration, endpoint controls, and incident response readiness — contact Sanjay Seth for a security assessment. With 30 years of hands-on experience in enterprise network security, zero-trust architecture, and NOC/SOC operations across India and the region, Sanjay can help you identify and close the gaps before a two-minute Teams call becomes your worst incident of the year.