Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact.
What Happened
Security vendor Sophos tracked the campaign to a financially motivated cluster designated STAC4749, active between February and June 2026 against organizations across professional services, manufacturing, energy, construction, engineering and intellectual-property law. The attackers impersonated internal IT helpdesk staff via Microsoft Teams chat messages and voice calls — most fraudulent calls lasted only two to two-and-a-half minutes — and persuaded employees to launch remote monitoring and management (RMM) tools such as Quick Assist or similar remote-access software.
Once inside, STAC4749 deployed a modular malware toolkit covering system discovery, persistence, command execution, remote access and lateral movement. In at least three confirmed incidents, this escalated to full Chaos ransomware deployment; the fastest documented case went from initial vishing call to complete network encryption in under 17 hours. Nearly 95% of observed victims were based in Canada and the United States, though the technique itself is platform-based rather than region-specific. This Microsoft Teams vishing ransomware pattern requires no malicious attachment and no exploited software vulnerability — it relies entirely on a human being persuaded to open a legitimate remote-access tool.
Why It Matters
STAC4749 is the second distinct threat actor in 2026 to weaponize Microsoft Teams’ default external-communication settings as an initial-access vector — the first being the Iranian MOIS-linked MuddyWater campaign DIESEC covered in May, which used Teams screen-sharing to impersonate IT support and bypass MFA. Two unrelated actors, one nation-state and one financially motivated, independently converging on the same technique inside three months indicates a platform-configuration gap rather than an isolated APT trick: by default, Teams allows any external Microsoft 365 tenant to message or call internal users unless an organization explicitly restricts it.
For DACH Mittelstand, the sub-17-hour timeline from vishing call to ransomware encryption is the operative number. Most incident-response playbooks and cyber-insurance assumptions are still built around detection-and-containment windows measured in days, not hours — a gap that NIS2’s 24-hour early-warning reporting obligation was designed to close, but only for organizations whose detection tooling can actually see the compromise that fast.
What You Should Do Now
- In Teams Admin Center, restrict external access under Users → External Access to an explicit allow-list of trusted domains rather than leaving it open to all external Microsoft 365 tenants — this single change blocks unsolicited chat and call requests from unknown organizations.
- Verify exposure: review Teams admin logs for external chat or call requests from unrecognized tenants over the past 90 days, and check whether any employee-installed RMM tools (Quick Assist, AnyDesk, TeamViewer) were launched shortly after such contact.
- Mitigate via endpoint allow-listing: restrict which remote-access and RMM tools are permitted to execute at all, since STAC4749’s fastest path to ransomware ran entirely through legitimate, employee-installed remote-access software rather than custom malware.
- Monitor: configure SIEM alerting on first-time external Teams caller events combined with any RMM tool installation or execution within the following hour — this combination is the closest thing to a reliable early indicator this campaign has produced.
If any of these steps is not currently in place, treat it as an open gap rather than a theoretical risk — the underlying Teams default has been sitting unrestricted in most tenants since deployment, not a recent regression.
DIESEC Perspective
We keep seeing the same root cause across two unrelated 2026 campaigns now: organizations harden email against phishing but leave collaboration-platform defaults untouched, on the assumption that “internal” tools carry internal-only risk. Teams, like email before it, is now a full external-contact surface by default — and attackers have noticed faster than most IT departments have adjusted their settings.
Not sure whether your Teams external-access configuration and RMM tool allow-list actually close this gap? Contact DIESEC for a rapid collaboration-platform exposure review.
Sources: Sophos | BleepingComputer
Published: 2026-08-04 | Category: Ransomware & Extortion | ~4 min read

