Chaos Ransomware Deployed in Under 17 Hours via Microsoft Teams IT Support Scam
Cybersecurity firm Sophos has detailed a threat cluster, tracked as STAC4749, in which attackers impersonate IT support staff using external Microsoft Teams accounts to trick employees into granting remote access. The attacker initiates contact from a Teams account on a deceptive .top domain, then uses legitimate remote tools like Quick Assist and RemSupp to establish control over the victim's device. Once inside, they deploy PowerShell scripts, a PyArmor-obfuscated PyInstaller backdoor, multiple remote management tools, and a reverse SOCKS proxy to move laterally across the internal network. In at least one confirmed case, the attackers exfiltrated data before simultaneously encrypting multiple devices with Chaos ransomware, completing the entire attack in under 17 hours. Sophos recommends restricting external Teams communications, enforcing strict application controls, and training users to verify IT staff identity before approving any remote support session.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in