Dozens of North American companies have been targeted in a social engineering campaign that abuses Microsoft Teams to deploy ransomware, according to a report by cybersecurity firm Sophos.
A threat group, tracked as STAC4749, has initiated chats or calls through Microsoft Teams under the guise of providing help desk or IT support to companies in the U.S. and Canada.
After initiating a remote session through Microsoft Quick Assist or the cloud-based RemSupp tool, hackers deploy PowerShell in order to establish persistence and execute malicious payloads.
The attacks come months after a Rapid7 report of Iran-linked MuddyWater conducting a false-flag campaign where they presented themselves as financially motivated actors. Sophos researchers explored possible links, but they believe the STAC4749 attacks are actually linked to a criminal actor.
“Based on the evidence we observed, this activity is most consistent with a financially motivated cybercriminal operation rather than state-sponsored actors,” said Morgan Demboski, threat intelligence analyst at Sophos. “Data was stolen in a subset of intrusions, but we did not observe behavior typically associated with espionage-focused actors, like long-term persistence, efforts at covert access, or targeted intelligence collection.”
The attacks were consistent with double-extortion operations that prioritize speed, according to Demboski.
In at least three cases, the hackers deployed Chaos ransomware on a compromised system. Researchers said in one of the cases, the time between initial access to deployment of ransomware was 17 hours, which is consistent with prior Chaos cases.
The observed attacks ran between February and June, targeting organizations in the services, manufacturing, energy, construction and engineering sectors.
Chaos ransomware-as-a-service has been active since February 2025 and has been linked to former members of BlackSuit ransomware, according to Sophos. Several of the tactics used in the recent campaign align with prior attacks connected to Chaos, including the use of Microsoft Teams along with Quick Assist for vishing. Prior attacks have also employed DWAgent and AnyDesk for lateral movement, according to Sophos.