Teams Vishing to Ransomware in 17 Hours: Help Desk Identity Controls

Sophos tracks STAC4749, a campaign in which external Microsoft Teams accounts impersonated IT help desks across dozens of organisations between February and June 2026, with at least three intrusions ending in Chaos ransomware. A six-point identity control playbook for internal and outsourced service desks.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai

Teams Vishing to Ransomware in 17 Hours: Help Desk Identity Controls

Sophos tracks STAC4749, a campaign in which external Microsoft Teams accounts impersonated IT help desks across dozens of organisations between February and June 2026, with at least three intrusions ending in Chaos ransomware. A six-point identity control playbook for internal and outsourced service desks.

Preguntas Frecuentes

What is STAC4749?

STAC4749 is the designation Sophos uses for a social-engineering campaign in which external Microsoft Teams accounts impersonated internal IT help desks in chat and by voice call. According to a Sophos report relayed by BleepingComputer on 30 July 2026, the campaign targeted dozens of organisations between February and June 2026. Sophos states it found no evidence linking STAC4749 to MuddyWater.

Who was targeted by the Teams help desk impersonation campaign?

According to Sophos, roughly 95% of the attacks targeted organisations in Canada (50%) and the United States (45%). The sectors most affected, per Sophos, were services, manufacturing, energy, and construction and engineering.

How did the attackers obtain remote access?

Sophos reports the objective of each call was to have the target start a remote support session via Microsoft Quick Assist, or install another RMM tool. Calls observed by Sophos lasted between 90 seconds and more than 20 minutes, most around two to two and a half minutes. Sophos notes the operators initially preferred Quick Assist and shifted mainly to the cloud tool RemSupp from April onwards, probably because it was less likely to be on an application blocklist.

What did the attackers do after gaining access?

Sophos describes PowerShell used to download a backdoor into %AppData%, persistence via registry entries disguised as audio components with names such as Realtek HD Audio, Realtek Audio UHD and WinAudio life2, installation of DWAgent or AnyDesk as fallback access, and attempts to enable RDP for lateral movement.

How quickly did the intrusions escalate to ransomware?

Sophos reports that at least three of these intrusions ended in deployment of the Chaos ransomware, and that in one case fewer than 17 hours elapsed between the first Microsoft Teams contact and encryption. Sophos indicates the Chaos ransomware-as-a-service operation has been active since at least February 2025 and is believed to be linked to former members of BlackSuit and Royal.

What should a buyer require from an outsourced service desk?

A documented bidirectional identification procedure with a company-side challenge phrase, a single technically enforced remote-control tool with application control blocking all alternatives, complete session logging exportable to the client SIEM, a defined escalation path with committed times on suspected impersonation, and periodic impersonation testing of the partner's own agents with results shared.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777