Published on July 30, 2026
A Two-Minute Microsoft Teams Call Could End with Your Network Encrypted with Ransomware
Severity
Medium
Detail
Cybersecurity researchers have identified an active ransomware campaign, tracked as STAC4749, in which threat actors exploit Microsoft Teams voice calls and chats to gain initial access to corporate environments. The attackers impersonate legitimate IT support personnel and convince employees to grant remote access through trusted remote assistance tools such as Microsoft Quick Assist.
Unlike traditional phishing campaigns that rely on malicious email attachments or links, this campaign leverages social engineering through collaboration platforms. Following successful remote access, attackers deploy custom malware, establish persistence, move laterally across the network, and ultimately encrypt systems using Chaos ransomware.
The campaign targeted dozens of organizations in North America between February and June 2026, with some incidents progressing from initial compromise to ransomware deployment in less than 17 hours.
How?
The attack begins when threat actors initiate a Microsoft Teams chat or voice call while impersonating legitimate IT support personnel using convincing employee names and IT-themed domains. During the conversation, they persuade the victim to approve a remote assistance session through Microsoft Quick Assist or another remote administration tool.
Once access is granted, the attackers perform system reconnaissance, identify installed security products, and enable Remote Desktop Protocol (RDP) to facilitate further access. They then deploy custom malware, establish persistence using Startup folder shortcuts and Registry Run keys, and install additional remote access tools, including a reverse SOCKS proxy, to maintain long-term control of the compromised environment. After moving laterally across the network, the attackers deploy Chaos ransomware, encrypting multiple systems simultaneously while continuously changing filenames and persistence techniques to evade detection.
Indicator of Compromise (IoC)
The following are Indicators of Compromise (IOCs) have been identified:
| IOC Type | Indicator | Description |
| Domain | sequrityupdate[.]top | IT-themed domain used by spoofed Microsoft Teams support accounts |
| IP Address | 94.140.114[.]192:443 | Hardcoded command-and-control (C2) server. |
| URL | hxxps://fa5[.]flsdwnld[.]online/f5yxog/confirm[.]exe | Python-based backdoor |
| File Name | updater.exe | |
| File Name | Readme[.]chaos[.]txt | Chaos ransomware ransom note filename |
Recommendation
Organizations should implement a layered security approach to reduce the risk of Teams voice phishing and ransomware attacks:
- Verify all Microsoft Teams support requests through official internal communication channels before approving remote assistance sessions.
- Restrict or disable Microsoft Quick Assist where it is not operationally required and control the use of remote administration tools.
- Educate users to treat unexpected Teams chats, voice calls, and remote access requests as suspicious.
- Monitor for unauthorized PowerShell execution, command-line activity, and remote administration software.
- Detect abnormal enabling of Remote Desktop Protocol (RDP) and unauthorized remote access sessions.
Source
https://cybersecuritynews.com/a-two-minute-microsoft-teams-call/
