
Fake IT Support Hits Teams to Drop Ransomware
Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked…
Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions. After gaining access, the attackers ran commands to download malware and in several cases deployed Chaos ransomware within hours. The activity (tracked as STAC4749) hit dozens of organizations, mainly in the US and Canada, across multiple sectors including services, manufacturing, energy, construction/engineering, and law firms.
This campaign, tracked as STAC4749, began with first contact through Microsoft Teams chats and calls in which operators impersonated helpdesk or IT support staff. The pretext was simple: a support issue needed fixing, and the target had to start a remote session. Operators created IT-themed cloud domains under the ".top" top-level domain and used plausible employee usernames to make their accounts look legitimate to targets who had no reason to doubt an internal IT contact.
Once a remote session was underway, either through an existing remote-access tool or one the victim was persuaded to download, the operators launched PowerShell on the compromised system. This was used to retrieve and execute malicious payloads hosted on attacker-controlled web servers. These payloads were typically staged in user-writable directories, most commonly AppData\Roaming, which let the activity blend into normal user file locations rather than requiring elevated access.
The attack relied on a pretext that employees encounter regularly: an IT support request. Because it arrived through Teams, a trusted internal collaboration tool, and used a professional-sounding username plus a domain designed to look IT-related, it bypassed the skepticism that might apply to an unfamiliar email or phone number. The request to start a remote session or install a tool did not necessarily look out of place if the target believed they were speaking with real IT staff.
Organizations affected spanned services, manufacturing, energy, construction and engineering, and legal services, showing this pretext can reach nearly any employee, not just technical staff. Because at least three compromises led to Chaos ransomware deployment, in one case less than 17 hours after initial access, the window to detect and stop this activity is short.
Defenders should train employees to treat unsolicited IT support contact on Teams as unverified until confirmed through a known internal channel, such as a direct call to the IT helpdesk using a number already on file. Staff should also be reminded that legitimate IT support rarely requires urgent action mid-chat, and that new remote-access tools should never be installed without separate confirmation. Reporting suspicious remote-support requests immediately, rather than after the fact, gives security teams a better chance to intervene before payloads execute.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers made first contact through Teams chats and calls, impersonating helpdesk or IT support staff, and used IT-themed ".top" domains with plausible employee usernames to appear legitimate.
They launched PowerShell on the compromised system to retrieve and execute malicious payloads from attacker-controlled web servers, typically staged in user-writable directories like AppData\Roaming.
In at least three compromises, attackers deployed Chaos ransomware, with one case occurring less than 17 hours after initial access.
The campaign hit dozens of organizations across services, manufacturing, energy, construction/engineering, and law firms, with all employees and IT helpdesk staff being common targets.
You’re in Teams, and a call pops up: “Hi, this is IT Support. We need to start a quick remote session to fix an issue.” Sophos saw this for real: STAC4749 used fake IT accounts from IT-themed .top domains in Teams, got remote access, then ran PowerShell to pull malware and push Chaos ransomware in under a day. Here’s the trick: first contact is an unsolicited Teams chat or call, they insist on a remote session or new remote tool, then quietly run scripts from AppData\Roaming while you think they’re 'fixing' something. If anyone on Teams asks for a remote session out of the blue, hang up and message our real IT team through our normal channel to confirm before you do anything.

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…