Microsoft Teams calls trick users into Chaos ransomware

Published July 30, 2026

Attackers pose as IT helpdesk staff in Microsoft Teams calls and trick employees into handing over remote access to their work computers. In several cases they used that access to lock up company files with Chaos ransomware.

Report priority
High
Victim
Microsoft
Group
Microsoft Teams calls trick users into Chaos

What is known

The attackers set up Teams accounts on lookalike IT-support domains, call or message an employee claiming to be internal support, then talk them into opening Microsoft Quick Assist or installing a remote-access tool called RemSupp, which hands the attacker control of the computer.

What to do

If you or a coworker got an unexpected Teams call or chat from an external account claiming to be IT support, especially one pushing you to open Quick Assist or install a tool called RemSupp, treat it as a likely attack.

Never grant Quick Assist control or install remote-access software for someone who contacted you first, verify any IT request through your organization's known helpdesk channel, and flag Teams contacts from unfamiliar domains, including ones ending in.top, to your security team.

Reported details

An outside Teams account posing as IT support calls an employee about a fake system problem. The caller talks the employee into opening Quick Assist, or installing the remote tool RemSupp, and takes control of the machine. Using that access, the attackers run PowerShell commands that plant a hidden backdoor in the AppData folder, disguised as fake Realtek or Windows audio drivers. Sophos found at least three of these intrusions led to Chaos ransomware locking up files, with one case going from the first call to full encryption in under 17 hours.

Sophos tracks this campaign as STAC4749, active February through June 2026. Operators registered '.top' domains such as and, using fake support personas like Anthony Brooks and Dylan Harper to vish employees over Teams. Initial access relied on Quick Assist, then shifted mainly to the cloud tool RemSupp after April, likely to avoid application blocklists.

Attackers used PowerShell to drop a backdoor into %AppData%, persisting under registry entries disguised as 'Realtek HD Audio' or 'WinAudio life2'. At least three of dozens of intrusions escalated to Chaos ransomware, one within 17 hours, with likely data theft before encryption in one case.