Back to feed
Dev.to
Dev.to
7/31/2026
STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam

STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam

Short summary

The STAC4749 threat group deploys Chaos ransomware within 17 hours by impersonating IT support through external Microsoft Teams calls. Attackers use Quick Assist or RemSupp to gain remote control, then deploy PowerShell loaders, PyInstaller backdoors, reverse SOCKS proxies, and multiple RMM tools for lateral movement before simultaneous encryption. Organizations should restrict external Teams contact, control RMM tools, and isolate compromised devices quickly.

  • Attackers impersonate IT support via external Teams calls to gain remote access using Quick Assist or RemSupp
  • Full chain from initial contact to Chaos ransomware encryption completes in under 17 hours
  • Mitigations include restricting external Teams federation, controlling RMM tools, and rapid device isolation

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more