
Security researchers at Sophos have documented a campaign they call STAC4749 in which attackers use Microsoft Teams voice calls to impersonate IT helpdesk staff and convince employees to hand over remote control of their computers. Once inside, they deploy Chaos ransomware. The campaign ran from February to June 2026, targeting dozens of organizations across North America — roughly half in Canada, just under half in the US — with at least three attacks advancing all the way to ransomware deployment. In the fastest observed case, attackers went from the first Teams call to encrypting files in under 17 hours.
The playbook is deliberate and methodical. Unlike past Teams-based social engineering attacks that used Microsoft’s own onmicrosoft.com domain to create fake accounts, STAC4749 registered IT-themed domains ending in .top (examples shared by Sophos include sequrityupdate[.]top, scan-security[.]top, and corp-connect[.]top), each paired with fake technician personas using names like Anthony Brooks and Dylan Harper. Calls lasted anywhere from 90 seconds to over 20 minutes. The goal was always the same: get the employee to launch Microsoft Quick Assist or install a remote monitoring tool called RemSupp. After gaining remote access, the attackers used PowerShell to download a backdoor into the user’s %AppData% folder, establishing persistence before eventually deploying ransomware. The attacker group switched from Quick Assist to RemSupp around April 2026, likely because RemSupp is less commonly blocked by corporate security policies.
How to check if you’re affected
Affected devices are any corporate Windows machines where an employee was contacted via Teams by an unrecognized external caller claiming to be IT support and was then prompted to run Quick Assist or install a remote tool. Check the %AppData% folder for unfamiliar executables or folders created around the time of a suspicious call. Look for RemSupp (remsuppsvc.exe or similar) in running processes or startup entries. Organizations should also review Teams external access logs for calls originating from .top domains like sequrityupdate[.]top or scan-security[.]top, and verify whether Quick Assist was recently launched on employee machines.
