Executive Summary
Between February and June 2026, a financially motivated campaign tracked as STAC4749 targeted dozens of North American organizations, primarily in Canada and the U.S. The attackers utilize Microsoft Teams voice phishing (vishing) to impersonate helpdesk personnel, engineering users into granting remote access via Microsoft Quick Assist or RemSupp. This initial access is leveraged to deploy a modular toolset including custom Python-based backdoors and Golang implants, frequently culminating in the deployment of Chaos ransomware.
The operation shows high technical maturity, characterized by rapid iteration of evasion techniques, including DLL sideloading and certificate pinning to secure C2 infrastructure. The speed of these attacks is notable, with some incidents progressing from initial contact to full ransomware encryption in under 17 hours. Impacted sectors include manufacturing, services, energy, and construction, with a specific focus on intellectual property law firms.
While there are reports suggesting Chaos might be used as a decoy by other groups, Sophos analysts maintain high confidence that STAC4749 is a distinct, financially motivated operation, likely involving former members of the BlackSuit (Royal) ransomware group.
Key Details
Threat Name
STAC4749 Chaos Campaign
Affects
—
Adversary
STAC4749 Other Adversaries and Aliases: GOLD REBELLION; STAC5777; STAC5143; MuddyWater; Black Basta; BlackSuit; Royal ransomware gang
MITRE Techniques
Malware/Tools
Chaos, Black Basta, 3AM, STAC4749 backdoor, STAC4749 loader, STAC4749 tunneling tool, STAC4749 C2 implant, EtherRAT, Golang implant, reverse SOCKS proxy
