Cybercriminals are calling employees through Microsoft Teams, impersonating internal IT support and deploying ransomware within hours of gaining access. Sophos has linked the campaign which it tracks as STAC4749, to former members of the BlackSuit and Royal ransomware gangs and says the attacks ran from at least February through June 2025, targeting organisations across multiple sectors in North America.
The method is direct. Attackers contact employees over Teams voice calls, claim to be from the IT helpdesk and walk the target through granting remote access to their device. No malware is required to get in. No vulnerability is exploited. The employee hands over access willingly because the caller sounds credible and is using a platform the organisation already trusts.
Once inside, the attackers move fast. According to Sophos, the interval between initial access and ransomware encryption is short enough that the firm assesses with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates to do so.
Why Teams Makes This Work
Email phishing has been a known threat for two decades. Most employees have been trained to scrutinise unexpected emails. Voice calls through a corporate platform are a different social context. Teams carries an implicit legitimacy that email does not, it comes from inside the environment, it uses the company directory and it feels like a real conversation rather than a suspicious message.
Attackers exploiting that trust gap is not new in concept. Scattered Spider used the same logic to compromise M&S in April 2025 calling a third-party helpdesk and talking their way into a password reset. What STAC4749 demonstrates is that the same social engineering approach is being industrialised through Teams specifically with Chaos ransomware-as-a-service as the payload.
Chaos ransomware-as-a-service has been active since at least February 2025, according to BleepingComputer. The RaaS model means the group behind STAC4749 does not need to build or maintain the ransomware itself. They source access, hand it off or deploy directly and split revenue with affiliates. That structure lowers the barrier to entry and makes attribution harder.
BlackSuit and Royal Connections
Sophos’s attribution to former BlackSuit and Royal members is significant. Royal ransomware was one of the more active groups targeting critical infrastructure in 2023 and 2024. BlackSuit emerged as its likely successor. If Sophos is right that STAC4749 draws from that talent pool, this campaign inherits operational experience from groups that have previously hit hospitals, schools and local government in the US and UK.
That said, Sophos is a commercial security vendor with products to sell and reports to publish. The BlackSuit and Royal connection is their analytical assessment not a law enforcement finding. It is worth reading the attribution carefully rather than treating it as settled.
The Configuration Change That Removes the Risk
Microsoft Teams, by default, allows users outside an organisation’s tenant to initiate chats and calls with internal users. That setting is what makes this attack possible at scale. An attacker with any Microsoft account can reach your employees directly unless external access is explicitly restricted.
Restrict external Teams communication to known, approved domains only. This is a tenant-level configuration in the Microsoft Teams admin centre under External Access settings. If your organisation has no legitimate reason to receive inbound Teams contacts from arbitrary external parties, disable the capability entirely.
Separately, audit which employees have permission to grant remote desktop or remote assistance access to their machines and ensure that any legitimate IT support workflow requires verification through a channel the employee initiates not one the caller controls. A helpdesk caller asking you to open a remote access tool should trigger the same scepticism as an email asking you to click a link.
Remote monitoring and management tools were the access vector in many of the confirmed STAC4749 incidents according to reporting by Cybersecurity Dive. Check which RMM tools are installed across your estate. Any that are not actively used by your IT team should be removed.
References
- Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Attacks
- Hackers Abuse Microsoft Teams in Ransomware Campaign Through Fake IT Support
- Teams Vishing Leads to Chaos Ransomware Attacks
This post is also available in: