Teams IT Vishing Drops Chaos Ransomware on US Firms
Microsoft Teams vishing campaign impersonates IT support, gains remote access, and drops Chaos ransomware on North American organizations.
Active. Confirmed.
Threat actors are initiating unsolicited Microsoft Teams calls, impersonating internal IT or help-desk staff, and social-engineering employees into granting remote device access. Once in, they deploy Chaos ransomware. Targets are North American organizations. BleepingComputer reported the campaign on July 30, 2026.
Confidence
- Confirmed: Active campaign targeting North American organizations, per BleepingComputer.
- Confirmed: Initial access is vishing via Teams calls — attackers posing as IT support.
- Confirmed: Chaos ransomware is the deployed payload.
- Unconfirmed: Specific threat actor identity — no attribution published yet.
Attack chain
Caller fabricates an IT pretext — security incident, account lockout, system flag — to manufacture urgency. Victim is walked through granting remote access. Attacker uses that access to stage and execute Chaos ransomware.
No software vulnerability exploited. This is pure social engineering, which makes perimeter tooling irrelevant to stopping it.
Teams-based vishing follows a documented playbook. Storm-1811 and various Black Basta affiliates used Microsoft Teams as a vishing vector beginning mid-2024, typically pairing it with Windows Quick Assist for remote access. This campaign extends the same approach with a different ransomware payload. For context on Chaos group tooling development, see msaRAT’s browser-based C2 channel.
What to do
For end users: Legitimate IT will not cold-call via Teams and immediately request remote access. No prior ticket or known incident → don’t comply. If in doubt, hang up and call the IT help desk back on a number from the internal directory.
For admins:
- Audit your Microsoft 365 external access settings. If your org doesn’t require inbound calls from external Teams tenants, disable it: Teams Admin Center → External Access.
- If Quick Assist isn’t your org’s standard remote support tool, remove or restrict it — Microsoft documents how to block it via Group Policy or Windows features.
- Confirm that remote support requests from IT require an existing ticket number the employee can verify independently.
If access was granted to an unverified caller: Treat the device as compromised. Isolate, review, engage incident response. Do not wait for ransomware indicators — by the time the note appears, the dwell is over.
Teams vishing has been a live attack vector for nearly two years. If security awareness training hasn’t addressed it, this campaign is the reason to update it this week.
Full campaign details: BleepingComputer.
Found this useful? Share it.


