
Fake Teams “IT Support” Calls Hijack PCs via Quick Assist
Attackers are calling employees on Microsoft Teams while pretending to be internal IT support, then persuading them to approve a Microsoft Quick Assist…
Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked into starting remote-control sessions (Quick Assist or RemSupp), after which the attackers used PowerShell to maintain access and, in some cases, deploy Chaos ransomware quickly (as little as 17 hours after first access).
A threat group tracked as STAC4749 ran a months-long social engineering campaign against companies in the U.S. and Canada. The attackers initiated chats or calls through Microsoft Teams while posing as help desk or IT support staff. Once a victim engaged, they were guided into starting a remote-control session using Microsoft Quick Assist or the cloud-based RemSupp tool. From there, attackers used PowerShell to establish persistence and execute malicious payloads on the compromised system.
In at least three intrusions, the attackers deployed Chaos ransomware. In one documented case, the time between initial access and ransomware deployment was only 17 hours, a pace consistent with double-extortion operations that prioritize speed over prolonged dwell time.
The campaign relied on trust in a familiar internal channel, Microsoft Teams, rather than external email or phone calls that employees are more commonly trained to scrutinize. Because the outreach appeared to come through a workplace collaboration tool, victims had less reason to question it before agreeing to a remote support session. Once remote access was granted, the technical steps that followed, PowerShell execution and persistence, happened quickly and largely out of the victim's view.
Targeted sectors included services, manufacturing, energy, construction, and engineering, industries where operational staff may have frequent, legitimate need for IT support and less exposure to security-specific training compared to office-based roles.
Organizations across affected sectors, including services, manufacturing, energy, construction, and engineering, should reinforce a few habits with employees:
Building these habits into routine awareness training can reduce the window of opportunity attackers rely on when speed is the goal. See T1566.003, T1219, and T1059.001 for related technique references.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers posing as help desk or IT support initiated chats or calls through Microsoft Teams, then guided victims into starting a remote session using Microsoft Quick Assist or the RemSupp tool.
In at least one case, the time between initial access and ransomware deployment was as little as 17 hours, consistent with double-extortion operations that prioritize speed.
Targeted sectors included services, manufacturing, energy, construction, and engineering, with activity observed between February and June.
Treat unsolicited Teams IT support chats or calls as suspicious, avoid starting remote sessions on request, and verify the request through a known internal help desk channel before engaging.
You get a Teams ping: “Hi, this is IT support, can you join a quick remote session?” Looks normal, right? Researchers saw a group called STAC4749 doing this for months on Teams, posing as help desk, then walking people into Quick Assist or RemSupp so they can run PowerShell and drop Chaos ransomware, sometimes in just 17 hours. The tell: an unsolicited Teams chat or call claiming to be IT, no ticket number, and they push you fast into a remote-control session with Quick Assist or RemSupp so they can “fix” something right now. If “IT” hits you on Teams out of the blue, do one thing: stop, ignore the chat, and contact our help desk using the normal channel you already know, Teams doesn’t start support, you do.

Attackers are calling employees on Microsoft Teams while pretending to be internal IT support, then persuading them to approve a Microsoft Quick Assist…

Sophos reports a real Microsoft Teams voice-phishing campaign where attackers pretended to be IT support to convince employees to start remote-access sessions.…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…