Sophos detailed a campaign, tracked as STAC4749, in which attackers impersonate IT help desk staff over Microsoft Teams to talk employees into granting remote access, then deploy Chaos ransomware. Using external Teams accounts, the operators start chats and voice calls claiming to fix an urgent problem, persuade the target to open a remote support session, and run PowerShell to pull down a modular toolkit for persistence and lateral movement. Between February and June 2026 they hit dozens of North American organizations, about 95 percent in the US and Canada, across services, manufacturing, energy, and construction. In one case they went from first contact to encrypting files in under seventeen hours.
Rapid7 disclosed an Iranian state-sponsored intrusion that disguised itself as a Chaos ransomware attack to mask the real goal: cyber-espionage. The threat actor (assessed with moderate confidence as MuddyWater, linked to Iran's Ministry of Intelligence and Security) initiated chat requests through Microsoft Teams, walked employees into screen-sharing sessions, then captured credentials and manipulated MFA prompts. Some victims were asked to type their passwords into local text files during the call. Persistence came from a custom backdoor (Game.exe) deployed alongside DWAgent, AnyDesk, and RDP. The fake ransomware note and Chaos leak-portal entry concealed the espionage.