< Back to all clusters
[CRIME] · United States, Canada · 6 sources

started · updated

Microsoft Teams ransomware campaign encrypts networks via two‑minute calls

A ransomware operation dubbed STST4749, tracked by Sophos, is using short Microsoft Teams voice or chat calls to trick employees into granting remote‑access sessions. Attackers impersonate IT help‑desk staff, persuade victims to approve Microsoft Quick Assist or other remote‑management tools, and then deploy the Chaos ransomware payload.

The campaign targeted dozens of organizations across North America between February and June 2026, with most fraudulent calls lasting only two to two‑and‑a‑half minutes. After gaining initial access, the operators run commands to harvest system information, disable security tools, and enable Remote Desktop Protocol for lateral movement. The malware evolved from a custom loader to a Python‑based backdoor delivered directly through the remote session, making detection harder. Sophos warns that the rapid, low‑effort social‑engineering technique highlights growing risks for firms that trust collaboration platforms by default.

Entities

Chaos ransomware · Microsoft · Microsoft Teams · STST4749 · Sophos