A coordinated cyberattack campaign involving voice phishing over Microsoft Teams has targeted dozens of organizations in North America, according to investigations by security firm Sophos. Tracked under the identifier STAC4749, the campaign ran between February and June 2026 and relied on social engineering tactics where threat actors impersonated IT support staff during Teams calls and chats to secure remote access to corporate devices.
Microsoft Teams Vishing Campaign Targets North American Organizations
Sophos observed that nearly 95% of the targeted organizations were located in Canada, which accounted for 50% of the cases, and the United States, which accounted for 45%. The attackers focused on a wide array of business sectors, with services, manufacturing, energy, and construction and engineering experiencing the highest volume of intrusions. Additionally, all legal organizations targeted in the campaign specialize in intellectual property law or services.
Tactics, Personas, and Infrastructure Used in STAC4749
The STAC4749 operators diverged from past campaigns by establishing IT-themed cloud domains under the “.top” top-level domain. Examples identified by BleepingComputer include sequrityupdate.top, scan-security.top, system-connect.top, corp-connect.top, and supportsoft.top.
Attackers paired these infrastructure components with fake IT support personas using specific aliases, including:
* Anthony Brooks * Dylan Harper * Ethan Parker * Jason Mitchell
During the initial contact, threat actors engaged victims in scam calls ranging from 90 seconds to over 20 minutes, with the majority lasting between two and two-and-a-half minutes. To establish control, the operators initially favored Microsoft Quick Assist. When Quick Assist was blocked or unavailable, they deployed the cloud-based RemSupp remote monitoring and management tool, shifting toward RemSupp more frequently after April because it is less likely to appear on application blocklists.
Post-Exploitation and Chaos Ransomware Deployment
Once attackers obtained remote access to employee devices, they utilized PowerShell to download a backdoor into the compromised user’s %AppData% folder. This malware profiled the system, established persistence, and maintained ongoing remote access. To mask these persistence mechanisms, malicious registry entries were given disguised names such as Realtek HD Audio,
Realtek Audio UHD,
and WinAudio life2.
In intrusions that escalated further, attackers installed remote access software like DWAgent or AnyDesk to serve as backup access points and attempted to enable the Remote Desktop Protocol to facilitate lateral movement across the network.
At least three of the intrusions resulted in the deployment of Chaos ransomware, which encrypted files simultaneously across compromised devices. Affected systems received ransom notes named readme.chaos.txt,
which claimed data had been stolen and warned that it would be leaked unless a ransom was paid. In one recorded incident, less than 17 hours elapsed between the initial Microsoft Teams contact and the final deployment of the ransomware.
Sophos analysts assessed with high confidence that the operation was financially motivated, noting that the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of the BlackSuit and Royal ransomware gangs, which were spinoffs from the Conti cybercrime syndicate.
