A cybersecurity alert highlights the activities of a threat actor group named STAC4749, associated with a Microsoft Teams vishing campaign that has resulted in multiple ransomware deployments using Chaos ransomware. Targeting dozens of organizations in North America, including Canada and the U.S., the attacks utilize fake IT support calls to gain remote access to victims' systems. The campaigns ran from February to June 2026, with notable tactics including using Quick Assist and later RemSupp for remote support.
The malware exploits PowerShell for data retention and establishes communication with command and control servers through Go-based implants. While financial motivation is presumed, attribution remains uncertain, as there is no definitive evidence linking STAC4749 to any known threat groups. To mitigate the risk, experts recommend skepticism towards unsolicited Teams calls and tightening restrictions on remote access tools.