Dev.to
7/31/2026

STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam
Short summary
The STAC4749 threat group deploys Chaos ransomware within 17 hours by impersonating IT support through external Microsoft Teams calls. Attackers use Quick Assist or RemSupp to gain remote control, then deploy PowerShell loaders, PyInstaller backdoors, reverse SOCKS proxies, and multiple RMM tools for lateral movement before simultaneous encryption. Organizations should restrict external Teams contact, control RMM tools, and isolate compromised devices quickly.
- •Attackers impersonate IT support via external Teams calls to gain remote access using Quick Assist or RemSupp
- •Full chain from initial contact to Chaos ransomware encryption completes in under 17 hours
- •Mitigations include restricting external Teams federation, controlling RMM tools, and rapid device isolation
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



