Cybersecurity Flash Notices

Microsoft Teams Impersonation and Chaos Ransomware Campaign

Written by Marketing | Aug 18, 2026, 4:59:30 PM

executive summary

Avertium is tracking STAC4749, a financially motivated intrusion campaign leveraging Microsoft Teams-based voice phishing (vishing), social engineering, and IT support impersonation to gain initial access to target environments. Public reporting links this activity to follow-on credential theft, unauthorized remote access, hands-on-keyboard intrusion activity, and deployment of Chaos ransomware against organizations across multiple industries and geographies. Rather than exploiting software vulnerabilities, the campaign abuses trusted communication channels and established business processes, using Microsoft Teams chats and calls to convince users they are interacting with legitimate Help Desk, IT Support, or security personnel. This activity reflects a broader trend of threat actors shifting initial access operations away from heavily monitored email channels and toward collaboration platforms that many organizations inherently trust.

 

why this matters

Microsoft Teams has become a critical business communication platform for organizations across healthcare, retail, manufacturing, financial services, and other sectors. Threat actors recognize that users often place greater trust in Teams communications than traditional email, making collaboration platforms an increasingly attractive target for social engineering operations.

This campaign is particularly relevant for Microsoft-centric organizations that rely heavily on remote support workflows, hybrid workforces, third-party collaboration, guest access, external tenant communications, and distributed operational teams. Unlike campaigns that require exploitation of a software vulnerability, STAC4749 weaponizes legitimate business processes and trusted communications to gain access.

Business Impact for Mid-Market Organizations

Successful compromise can result in credential theft, unauthorized remote access, ransomware deployment, operational disruption, regulatory exposure, loss of customer confidence, data recovery expenses, and potential extortion-related activity.

Likelihood of Exposure

Organizations utilizing Microsoft Teams federation, external access, guest accounts, remote support processes, and cross-tenant collaboration are more likely to encounter similar social engineering attempts. As defenders continue improving email security controls, threat actors are increasingly targeting collaboration platforms as alternative paths into enterprise environments.

Consequences of Inaction

Organizations that do not validate support interactions, restrict unnecessary external communications, or monitor collaboration-platform activity may remain vulnerable to attacks that bypass traditional phishing awareness programs and email-focused security controls. Once access is established, attackers may rapidly progress to credential theft, privilege escalation, lateral movement, and ransomware deployment.

Recent industry reporting further highlights that many organizations maintain external collaboration settings, guest access permissions, and cross-tenant communication pathways that receive significantly less security scrutiny than email systems. As organizations continue enabling business collaboration, Teams-specific governance, audit visibility, detection capabilities, and security controls should be evaluated with the same rigor traditionally applied to email security.

 

what we're seeing

Campaign Overview

Reporting associated with STAC4749 indicates threat actors are combining social engineering, user fatigue tactics, legitimate collaboration features, and remote access abuse to establish footholds within enterprise environments.

Plain-Language Kill Chain

Stage 1: User Disruption and Attention Manipulation

Threat actors may generate significant volumes of communications intended to overwhelm, distract, or frustrate targeted users. These activities increase the likelihood that a subsequent support interaction appears legitimate and receives less scrutiny.

Stage 2: Microsoft Teams Impersonation

Attackers initiate Teams chats, calls, meetings, or support interactions while impersonating Help Desk personnel, IT administrators, security teams, or third-party support resources. Collaboration platforms are increasingly being leveraged because users often perceive Teams communications as inherently trustworthy. In many cases, attackers rely on legitimate external communications and native collaboration features rather than malware delivery or exploit-based techniques, increasing the likelihood users engage before recognizing suspicious behavior.

Stage 3: User-Assisted Access

Once trust has been established, victims are persuaded to approve remote assistance requests, launch remote management tools, install software, grant permissions, share screens, or otherwise facilitate attacker access to organizational systems.

Stage 4: Credential Collection and Internal Discovery

Following initial access, operators seek credentials, enumerate systems, identify administrative users, map business systems, and gather information necessary to expand access throughout the environment.

Stage 5: Privilege Escalation and Lateral Movement

Threat actors seek broader access through compromised credentials, legitimate administration utilities, remote management capabilities, and trusted operational workflows commonly present in enterprise environments.

Stage 6: Ransomware Deployment and Extortion

Public reporting links this activity to deployment of Chaos ransomware, resulting in system encryption, operational disruption, business downtime, and extortion-related activity.

Client-Relevant Indicators

Because STAC4749 relies heavily on social engineering and legitimate platform functionality, behavioral indicators are generally more valuable than static indicators alone.

Organizations should treat the following activity as potentially suspicious:

  • Unsolicited Teams chats, calls, meetings, or messages claiming to originate from Help Desk, IT Support, Security Operations, administrators, or service providers.
  • Requests involving screen sharing, remote assistance, remote-control sessions, software installation, password resets, MFA troubleshooting, or administrative actions.
  • Communications creating urgency around account lockouts, security incidents, service outages, authentication failures, or system issues.
  • Unexpected external Teams communications from previously unknown organizations.
  • Requests to execute remote management tools following support-related interactions.
  • Support engagements that occur immediately after unusual surges in messaging, email, or communication activity.

 

risk and priority

Category

Assessment

Threat Severity (Technical)

High

Client Risk Relevance (Contextual)

High

Recommended Priority

Immediate


Rationale: This campaign leverages trusted business communication platforms and established support workflows rather than exploiting a specific software vulnerability. Because Microsoft Teams is widely deployed throughout Avertium client environments and the observed attack chain can lead directly to credential compromise, unauthorized access, and ransomware deployment, organizations should prioritize hardening collaboration pathways, reviewing external communication controls, and validating defensive coverage.

 

recommended actions

Immediate (0-72 Hours)

Organizations should review Microsoft Teams external communication settings and determine whether unrestricted communication with external tenants remains a documented business requirement. Restricting unnecessary external collaboration can significantly reduce exposure to impersonation attempts originating outside the organization.

  • Review Teams federation settings and identify which external organizations are currently permitted to communicate directly with users. Where feasible, limit external access to approved business partners and trusted organizations rather than allowing unrestricted communication with all Microsoft tenants.

  • Require employees to independently verify unsolicited support requests received through Teams, particularly when they involve screen sharing, remote assistance, password resets, MFA troubleshooting, account lockouts, software installation, or administrative actions. Users should leverage established support channels rather than relying solely on information presented during a Teams interaction.

  • Review recent Teams chats, meetings, calls, and support engagements for signs of unsolicited communications claiming to originate from internal IT personnel, security teams, administrators, or external service providers.

  • Confirm multifactor authentication is enabled for all users and verify that privileged administrators are protected through stronger authentication requirements and Conditional Access protections wherever possible.

  • Review remote support procedures and validate that users are not authorized to approve unsolicited requests involving Quick Assist, remote-control sessions, remote management software, screen sharing, or installation of remote access tools.

Near-Term (1-2 Weeks)

  • Conduct a review of guest access permissions and determine whether temporary collaborators, vendors, contractors, and external users maintain access beyond documented business requirements.

  • Assess cross-tenant collaboration policies and establish governance around trusted partner relationships. Organizations should understand which external tenants have communication privileges and periodically reassess whether those trust relationships remain necessary.

  • Review whether inbound communications from unmanaged Microsoft personal accounts remain necessary and disable access where business requirements do not justify the risk.

  • Evaluate whether Teams External Access should be limited to approved business domains rather than unrestricted federation with external organizations.

  • Evaluate who can initiate external chats, calls, meetings, screen-sharing sessions, and remote-control interactions with internal users.

  • Review Microsoft Teams and Microsoft 365 security controls that help identify impersonation attempts, suspicious messaging activity, abnormal collaboration behaviors, and indicators of social engineering activity.

  • Assess detection coverage for unauthorized remote access, remote management abuse, suspicious authentication activity, credential theft attempts, privilege escalation behaviors, and ransomware precursor activity.

  • Validate that audit logging and security telemetry from Microsoft Teams, Microsoft Entra ID, Microsoft 365, and endpoint security platforms are enabled, retained appropriately, and available to support investigations.

  • Verify that security teams maintain visibility into Teams administrative actions, external communications, collaboration activity, and related audit events.

  • Conduct focused awareness messaging that specifically addresses Teams-based social engineering techniques rather than focusing exclusively on email phishing.

  • Validate that employees understand how to report suspicious Teams calls, chats, meetings, support interactions, and screen-sharing requests through established security reporting processes.

Strategic (Programmatic)

  • Establish formal verification procedures for Help Desk and IT support interactions so users can consistently distinguish legitimate support activity from impersonation attempts. Administrative support personnel should utilize approved communication methods, recognizable workflows, and standardized naming conventions wherever possible.

  • Implement controlled cross-tenant collaboration governance and routinely reassess trusted external relationships.

  • Review privileged account management practices and ensure administrative accounts remain separated from standard user activity wherever possible.

  • Assess Conditional Access policies to determine whether identity protections adequately address high-risk sign-ins, unfamiliar locations, unmanaged devices, suspicious authentication patterns, and high-value administrative accounts.

  • Develop reporting procedures that allow employees to rapidly report suspicious Teams messages, chats, calls, meetings, and collaboration activity to internal security personnel or Avertium analysts.

  • Expand user awareness exercises to include realistic Teams-based social engineering scenarios involving Help Desk impersonation, remote assistance abuse, MFA-related fraud, collaboration-platform abuse, and external tenant impersonation.

  • Organizations should periodically review Teams governance, guest access management, collaboration monitoring capabilities, external communication permissions, and cross-tenant trust relationships as part of broader Microsoft 365 security posture assessments.

Organizations should also consider the following questions:

  1. Can any external Microsoft tenant directly call or chat organizational users?
  2. Do we know which external organizations and domains are currently trusted and why they remain trusted?
  3. How would an employee verify that a Teams message claiming to originate from IT is legitimate?
  4. Can external users initiate screen-sharing or remote-control sessions with employees?
  5. Are privileged administrators protected by stronger authentication controls than standard users?
  6. Would existing monitoring identify a user executing remote access software after receiving an unsolicited Teams call?
  7. Do security teams have visibility into external Teams chats, calls, meetings, and collaboration activity?
  8. Have employees been specifically trained to recognize Teams-based social engineering techniques?
  9. Do current Help Desk processes make legitimate support interactions easily distinguishable from impersonation attempts?

 

avertium value and coverage

Coverage Area

Details

Detections in Place Today

Avertium maintains detection coverage across Microsoft identity, authentication, endpoint, privilege escalation, suspicious remote access, ransomware-related behavior, and post-compromise activity commonly associated with campaigns such as STAC4749.

Under Active Monitoring

The Avertium SOC continuously monitors authentication anomalies, administrative activity, endpoint telemetry, suspicious remote access, abnormal privilege use, collaboration-related security events, and ransomware precursor activity across supported security platforms.

Being Tuned, Hunted, or Engineered

Avertium threat hunting and detection engineering teams continue evaluating emerging Teams-based social engineering techniques, collaboration-platform abuse methodologies, credential theft activity, and post-compromise behaviors associated with campaigns targeting Microsoft-centric organizations.

What the Client Does NOT Need to Worry About

Clients do not need to independently build custom detections for ransomware-related behaviors already covered through Avertium SOC monitoring and detection engineering efforts. Client efforts should instead focus on strengthening operational processes, user validation procedures, collaboration controls, and identity security practices that reduce the likelihood of successful social engineering attacks.

Need Assistance?

If your organization would like assistance assessing Microsoft Teams security controls, external collaboration settings, identity protections, or response readiness related to this activity, please contact your assigned Avertium Account Success Team (AST). Organizations that believe they may be experiencing suspicious activity or require immediate assistance should contact the Avertium Security Operations Center (SOC) at 1-877-707-7997, Option 1, for 24x7 support and incident escalation.

 

SUPPORTING DOCUMENTATION