Sophos tracks STAC4749, a campaign in which external Microsoft Teams accounts impersonated IT help desks across dozens of organisations between February and June 2026, with at least three intrusions ending in Chaos ransomware. A six-point identity control playbook for internal and outsourced service desks.
STAC4749 is the designation Sophos uses for a social-engineering campaign in which external Microsoft Teams accounts impersonated internal IT help desks in chat and by voice call. According to a Sophos report relayed by BleepingComputer on 30 July 2026, the campaign targeted dozens of organisations between February and June 2026. Sophos states it found no evidence linking STAC4749 to MuddyWater.
According to Sophos, roughly 95% of the attacks targeted organisations in Canada (50%) and the United States (45%). The sectors most affected, per Sophos, were services, manufacturing, energy, and construction and engineering.
Sophos reports the objective of each call was to have the target start a remote support session via Microsoft Quick Assist, or install another RMM tool. Calls observed by Sophos lasted between 90 seconds and more than 20 minutes, most around two to two and a half minutes. Sophos notes the operators initially preferred Quick Assist and shifted mainly to the cloud tool RemSupp from April onwards, probably because it was less likely to be on an application blocklist.
Sophos describes PowerShell used to download a backdoor into %AppData%, persistence via registry entries disguised as audio components with names such as Realtek HD Audio, Realtek Audio UHD and WinAudio life2, installation of DWAgent or AnyDesk as fallback access, and attempts to enable RDP for lateral movement.
Sophos reports that at least three of these intrusions ended in deployment of the Chaos ransomware, and that in one case fewer than 17 hours elapsed between the first Microsoft Teams contact and encryption. Sophos indicates the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of BlackSuit and Royal.
A documented bidirectional identification procedure with a company-side challenge phrase, a single technically enforced remote-control tool with application control blocking all alternatives, complete session logging exportable to the client SIEM, a defined escalation path with committed times on suspected impersonation, and periodic impersonation testing of the partner's own agents with results shared.
CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777