Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Attacks

Threat actors are conducting vishing attacks via Microsoft Teams by impersonating IT support staff to gain remote access to corporate devices, leading to Chaos ransomware infections in North American organizations. The campaign, tracked as STAC4749 by Sophos, targeted mainly Canadian and US companies across multiple sectors, using fake IT domains and remote support tools like Microsoft Quick Assist and RemSupp to deploy backdoors and achieve persistence before deploying ransomware. Some attacks resulted in data theft and rapid ransomware encryption within 17 hours of initial access.

https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top