STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment — Threadlinqs Intelligence
As of 2026-07-30, STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment is a high-severity ransomware threat attributed to STAC4749, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-1776 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: STAC4749 · FINANCIAL
Tracked by Sophos as STAC4749, a financially motivated actor cluster assessed to include former BlackSuit/Royal (Conti-lineage) ransomware members has run a Microsoft Teams vishing campaign since
Between February and June 2026, Sophos X-Ops tracked a Microsoft Teams voice-phishing (vishing) campaign, designated STAC4749, that impersonated corporate IT helpdesk staff over external Teams calls to social-engineer employees into launching remote-access sessions. Operators used short, scripted calls (typically 2-2.5 minutes, ranging 90 seconds to 20+ minutes) from Teams accounts using invented personas (e.g. AnthonyBrooks, DylanHarper, EthanParker, JasonMitchell, and a dozen other randomized names) and referenced lookalike '.top'-TLD domains styled as internal IT/security portals (sequrityupdate[.]top, scan-security[.]top, system-online[.]top, system-connect[.]top, corp-connect[.]top, info-secure[.]top, supportsoft[.]top, update-syscontrol[.]top, and others) to add legitimacy.
Once a victim launched a remote-support session, operators initially relied on Microsoft Quick Assist (later phased out as it became blocklisted by defenders), before shifting primarily to the commercial cloud RMM tool RemSupp (remsupp.com) from April 2026 onward. DWAgent (dwservice.net) and AnyDesk (anydesk.com) were layered in for backup access and lateral movement, and RDP was enabled on compromised hosts via msconfig changes.
During the remote session, operators used PowerShell to pull first-stage loaders into %AppData%. Loader filenames rotated on a roughly two-to-four-week cadence to evade static detection: sekv_<10-digit>.exe (Feb-Mar), helper_<10-digit>.exe (Mar 26-Apr 9), and 74fs_<10-digit>.exe (Apr 10-13). These gRPC-speaking loaders hard-coded C2 IPs 94.140.114.192, 94.140.115.18 and 94.140.115.129 on port 443, performed host fingerprinting, generated a per-sample mutex, and checked for a dependency marker at C:\ProgramData\AppSreen\logs\appscreen.log before staging further payloads under AppData\Roaming. From mid-April, STAC4749 abandoned the standalone-loader step and pushed backdoors directly.
Persistence was established via HKCU Run keys disguised as audio-driver services -- 'Realtek HD Audio Universal Service', 'Realtek HD Audio', 'Realtek Audio', 'Realtek Audio UHD', and 'WinAudio life2' -- each pointing at the current-generation loader/backdoor binary, supplemented by VBS scripts (mklink-%.vbs) that dropped Startup-folder shortcuts disguised as SecurityHealth or OneDriveUpdate, with hidden file attributes applied selectively. Host discovery activity included computer-name/Machine-GUID collection, HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion enumeration, OS version queries, running-process enumeration, file/directory discovery, remote-system and domain-trust discovery, network-share discovery, and active security-product detection.
The primary C2 implant evolved along two tracks: a PyArmor-obfuscated, PyInstaller-packaged Python backdoor (updater.exe, 7414fs*.exe, 45234ssdf403851640.exe, msupdate.exe) that decrypted its AES-encrypted configuration using keys/IVs staged on a public GitHub repository and a workers[.]dev-hosted C2 channel; and a family of Golang implants named with single common nouns (dizzy.exe, graph.exe, tube.exe, confirm.exe, midnight.exe, shield.exe), deployed via a PowerShell one-liner pulling from attacker infrastructure (e.g. fa5[.]flsdwnld[.]online) and authenticating to C2 with a base64-encoded '--token-raw' argument, pinning connections to hard-coded CA certificate issuers (loop-CA, connectify-CA, james-bond-CA) so that mismatched issuers routed to segregated backend infrastructure. In incidents that escalated to ransomware, operators additionally deployed sc5.exe, a reverse SOCKS proxy supporting up to 1,000 concurrent connections, communicating with infrastructure at legio[.]name.
Data was staged and exfiltrated using a renamed/disguised GoodSync binary prior to encryption. Ransomware deployment used Chaos, a C++ ransomware-as-a-service family that re-emerged in February 2025 and which Cisco Talos and others assess with moderate confidence is operated by former BlackSuit (itself a Royal/Conti-line
Target sectors: services, manufacturing, energy, construction, engineering, legal services, intellectual property law
Target regions: North America, canada, united states of america
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1585.001, T1566.004, T1133, T1059.001, T1059.003, T1047, T1547.001, T1547.009, T1547.001