# The IT Guy Was a Threat Actor: How STAC4749 Turned Microsoft Teams Into a Ransomware On-Ramp
Your employees are already suspicious of email. They've been trained to squint at links, hover before clicking, and think twice before downloading attachments. So attackers stopped using email.
A campaign tracked by Sophos as STAC4749 spent five months — February through June 2026 — walking straight in through the front door of Microsoft Teams, calling employees directly, pretending to be IT support, and talking their way onto corporate devices. At least three of those intrusions ended with Chaos ransomware encrypting files across the network. One of them went from first phone call to full encryption in under 17 hours.
## Who Picked Up the Phone
The targets were overwhelmingly North American: half Canadian organizations, 45 percent American. Services, manufacturing, energy, and construction took the most hits — sectors where IT departments are stretched thin and where an out-of-the-blue "helpdesk" call might not immediately raise flags.
The calls themselves were brief. Most lasted two to two-and-a-half minutes. Short enough to feel routine. Long enough to convince someone to open a remote support session.
The personas were specific: Anthony Brooks, Dylan Harper, Ethan Parker, Jason Mitchell. Not generic handles — actual constructed identities, each apparently paired with dedicated infrastructure. The domains they used moved away from Microsoft's own onmicrosoft.com namespace (which previous Teams-based campaigns favored) toward freshly registered .top TLD domains: sequrityupdate[.]top, scan-security[.]top, corp-connect[.]top. It's a small operational detail that reveals deliberate tradecraft — using Microsoft's own domain had started to look suspicious to defenders, so they pivoted.
## From "Click Here" to "Can You Share Your Screen?"
The social engineering goal was simple: get the target to launch a remote access session. The attackers' first tool of choice was Microsoft Quick Assist, a built-in Windows remote support utility that looks perfectly legitimate to most users and many security tools. When Quick Assist was unavailable or blocked, they switched to RemSupp, a cloud-based remote monitoring and management platform.
By April, RemSupp had become the primary tool. The reason Sophos suspects: Quick Assist had started appearing on corporate blocklists. Rather than fight the controls, STAC4749 sidestepped them entirely.
This is the part that should keep defenders up at night. The attackers weren't brute-forcing perimeters or exploiting unpatched CVEs. They were adapting their toolset in real time based on what got flagged. When one RMM tool got blocked, they queued up another.
## Backstage: What Happened After the Call Ended
Remote access established, the real work began quietly. A PowerShell script pulled a backdoor into the compromised user's %AppData% folder — a location that rarely triggers alerts because legitimate software writes there constantly. The backdoor profiled the system, phoned home, and dug in.
Persistence was disguised as audio drivers. Registry entries masquerading as "Realtek HD Audio" and "WinAudio life2" sat undisturbed because audio driver entries are exactly the kind of low-priority noise that doesn't make it into a SOC alert queue at 2 AM.
In the intrusions that escalated to ransomware, the attackers added redundancy: DWAgent or AnyDesk installed as backup remote access, Remote Desktop Protocol re-enabled on compromised hosts for lateral movement. By the time Chaos ransomware was deployed, the attackers had turned a single employee's device into a launchpad with multiple independent footholds across the environment.
The ransomware deployed simultaneously across compromised systems. Ransom notes — readme.chaos.txt — claimed data had already been exfiltrated and threatened public release. At least one confirmed case involved actual data theft before encryption.
## Seventeen Hours
That timeline deserves emphasis. Fewer than seventeen hours from an employee answering a Teams call to files encrypting across the organization. That's not slow, methodical intrusion. That's a practiced team running a repeatable playbook with very little friction in their way.
Traditional incident response assumptions — that you'll detect lateral movement, that you'll catch the exfiltration, that you'll have time to isolate systems — compress badly when the attacker is operating on a sub-day timeline.
---
## HackWire Analysis
STAC4749 didn't invent anything new. Vishing campaigns targeting corporate Teams environments go back at least to 2024, when a group linked to Black Basta used nearly identical social engineering — impersonating IT support, convincing employees to grant remote access — against hundreds of organizations. What STAC4749 demonstrates is maturation: the playbook is getting cleaner, faster, and more adaptive.
The shift from .onmicrosoft.com infrastructure to custom .top domains signals that the attackers are reading the same threat intelligence their targets' defenders are reading. When defenders added .onmicrosoft.com callouts to their Teams policies and training, the attackers updated their infrastructure. That feedback loop is functioning, and it's functioning faster than most enterprise security programs can respond.
The RMM tool rotation is the same story. Quick Assist gets blocklisted; RemSupp comes out. When RemSupp starts appearing in threat reports and blocklists proliferate, expect the next tool in the queue. Organizations that think blocking one RMM tool closes this vector are missing the point — the attack surface is any RMM tool a credible-sounding "IT support person" can convince an employee to install.
For defenders, the practical priority is this: Microsoft Teams external communication is enabled by default in most tenants, and most employees have no idea that someone outside their organization can initiate a Teams call with them. That's the first control to review. Restricting or auditing external Teams communications — combined with active employee training that specifically addresses voice and video social engineering, not just email phishing — closes the front door STAC4749 walked through.
SOC teams should treat any unsolicited remote access tool installation — even via legitimate software like Quick Assist — as a high-confidence alert trigger, not a low-priority event. The 17-hour clock starts the moment that session opens.
Finally: Chaos ransomware has been deployed by multiple unrelated threat actors. It's available to a range of operators, which means this campaign's tactics may proliferate well beyond STAC4749 itself. Defenders who treat this as one group's signature instead of a reusable playbook will be caught off guard when the next group runs the same script.
— HackWire Editorial
---
## Related Coverage