STAC4749 Teams Vishing Campaign Leading to Chaos Ransomware
Score: 9/10

STAC4749 Teams Vishing Campaign Leading to Chaos Ransomware

The threat actor STAC4749 uses Microsoft Teams vishing to impersonate IT support, gaining remote access to deploy custom loaders, backdoors, and Chaos ransomware targeting North American organizations.

Executive Summary

Between February and June 2026, a financially motivated campaign tracked as STAC4749 targeted dozens of North American organizations, primarily in Canada and the U.S. The attackers utilize Microsoft Teams voice phishing (vishing) to impersonate helpdesk personnel, engineering users into granting remote access via Microsoft Quick Assist or RemSupp. This initial access is leveraged to deploy a modular toolset including custom Python-based backdoors and Golang implants, frequently culminating in the deployment of Chaos ransomware.

The operation shows high technical maturity, characterized by rapid iteration of evasion techniques, including DLL sideloading and certificate pinning to secure C2 infrastructure. The speed of these attacks is notable, with some incidents progressing from initial contact to full ransomware encryption in under 17 hours. Impacted sectors include manufacturing, services, energy, and construction, with a specific focus on intellectual property law firms.

While there are reports suggesting Chaos might be used as a decoy by other groups, Sophos analysts maintain high confidence that STAC4749 is a distinct, financially motivated operation, likely involving former members of the BlackSuit (Royal) ransomware group.

Key Details

Threat Name

STAC4749 Chaos Campaign

Affects

—

Adversary

STAC4749 Other Adversaries and Aliases: GOLD REBELLION; STAC5777; STAC5143; MuddyWater; Black Basta; BlackSuit; Royal ransomware gang

Malware/Tools

Chaos, Black Basta, 3AM, STAC4749 backdoor, STAC4749 loader, STAC4749 tunneling tool, STAC4749 C2 implant, EtherRAT, Golang implant, reverse SOCKS proxy

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources