Hackers abuse Microsoft Teams in ransomware campaign through fake IT support

A cybercriminal group known as STAC4749 is using Microsoft Teams to conduct social engineering attacks against North American companies. The hackers pose as IT support to gain remote access and deploy ransomware.
Why it matters
This highlights a shift in cyberattack tactics, where common business communication tools are being weaponized for financial extortion.
Researchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.
Dozens of North American companies have been targeted in a social engineering campaign that abuses Microsoft Teams to deploy ransomware, according to a report by cybersecurity firm Sophos.
A threat group, tracked as STAC4749, has initiated chats or calls through Microsoft Teams under the guise of providing help desk or IT support to companies in the U.S. and Canada.
After initiating a remote session through Microsoft Quick Assist or the cloud-based RemSupp tool, hackers deploy PowerShell in order to establish persistence and execute malicious payloads.
The attacks come months after a Rapid7 report of Iran-linked MuddyWater conducting a false-flag campaign where they presented themselves as financially motivated actors. Sophos researchers explored possible links, but they believe the STAC4749 attacks are actually linked to a criminal actor.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in