Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign, STAC4749, breached dozens of firms via fake IT-helpdesk calls, encrypting networks within 17 hours.

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact.

What Happened

Security vendor Sophos tracked the campaign to a financially motivated cluster designated STAC4749, active between February and June 2026 against organizations across professional services, manufacturing, energy, construction, engineering and intellectual-property law. The attackers impersonated internal IT helpdesk staff via Microsoft Teams chat messages and voice calls — most fraudulent calls lasted only two to two-and-a-half minutes — and persuaded employees to launch remote monitoring and management (RMM) tools such as Quick Assist or similar remote-access software.

Once inside, STAC4749 deployed a modular malware toolkit covering system discovery, persistence, command execution, remote access and lateral movement. In at least three confirmed incidents, this escalated to full Chaos ransomware deployment; the fastest documented case went from initial vishing call to complete network encryption in under 17 hours. Nearly 95% of observed victims were based in Canada and the United States, though the technique itself is platform-based rather than region-specific. This Microsoft Teams vishing ransomware pattern requires no malicious attachment and no exploited software vulnerability — it relies entirely on a human being persuaded to open a legitimate remote-access tool.

Why It Matters

STAC4749 is the second distinct threat actor in 2026 to weaponize Microsoft Teams’ default external-communication settings as an initial-access vector — the first being the Iranian MOIS-linked MuddyWater campaign DIESEC covered in May, which used Teams screen-sharing to impersonate IT support and bypass MFA. Two unrelated actors, one nation-state and one financially motivated, independently converging on the same technique inside three months indicates a platform-configuration gap rather than an isolated APT trick: by default, Teams allows any external Microsoft 365 tenant to message or call internal users unless an organization explicitly restricts it.

For DACH Mittelstand, the sub-17-hour timeline from vishing call to ransomware encryption is the operative number. Most incident-response playbooks and cyber-insurance assumptions are still built around detection-and-containment windows measured in days, not hours — a gap that NIS2’s 24-hour early-warning reporting obligation was designed to close, but only for organizations whose detection tooling can actually see the compromise that fast.

What You Should Do Now

  1. In Teams Admin Center, restrict external access under Users → External Access to an explicit allow-list of trusted domains rather than leaving it open to all external Microsoft 365 tenants — this single change blocks unsolicited chat and call requests from unknown organizations.
  2. Verify exposure: review Teams admin logs for external chat or call requests from unrecognized tenants over the past 90 days, and check whether any employee-installed RMM tools (Quick Assist, AnyDesk, TeamViewer) were launched shortly after such contact.
  3. Mitigate via endpoint allow-listing: restrict which remote-access and RMM tools are permitted to execute at all, since STAC4749’s fastest path to ransomware ran entirely through legitimate, employee-installed remote-access software rather than custom malware.
  4. Monitor: configure SIEM alerting on first-time external Teams caller events combined with any RMM tool installation or execution within the following hour — this combination is the closest thing to a reliable early indicator this campaign has produced.

If any of these steps is not currently in place, treat it as an open gap rather than a theoretical risk — the underlying Teams default has been sitting unrestricted in most tenants since deployment, not a recent regression.

DIESEC Perspective

We keep seeing the same root cause across two unrelated 2026 campaigns now: organizations harden email against phishing but leave collaboration-platform defaults untouched, on the assumption that “internal” tools carry internal-only risk. Teams, like email before it, is now a full external-contact surface by default — and attackers have noticed faster than most IT departments have adjusted their settings.

Not sure whether your Teams external-access configuration and RMM tool allow-list actually close this gap? Contact DIESEC for a rapid collaboration-platform exposure review.

Sources: Sophos | BleepingComputer
Published: 2026-08-04 | Category: Ransomware & Extortion | ~4 min read