A Two-Minute Teams Call Is All It Takes to Get Ransomwared Now

A Two-Minute Teams Call Is All It Takes to Get Ransomwared Now

You know that mildly annoying "hi, this is IT, we need to check something on your machine" call? Turns out it's not always your actual help desk having a slow Tuesday. Sometimes it's a ransomware crew, and sometimes your entire network is encrypted before your coffee gets cold.

Meet STAC4749, the Chattiest Ransomware Crew Around

Security firm Sophos is tracking a campaign called STAC4749, in which attackers impersonate IT helpdesk staff over Microsoft Teams chats and voice calls, then talk employees into launching remote access tools or installing "support" software. Once they're in, some of these intrusions escalate to Chaos ransomware — a ransomware-as-a-service operation active since early 2025 and reportedly linked to former members of the BlackSuit and Royal gangs, themselves offshoots of the infamous Conti syndicate.

The numbers are the unsettling part: the calls themselves typically last just two to two-and-a-half minutes, the campaign hit dozens of organizations between February and June 2026 (95% split almost evenly between the US and Canada), and in at least one case the attackers went from first contact to fully encrypted files in under 17 hours.

Your Firewall Can't Stop a Convincing Voice

This is social engineering doing what social engineering always does best: skipping the technical defenses entirely and going straight for the one component every security stack still can't patch — a busy employee who just wants their laptop to work. No exploit, no malware attachment, no phishing link. Just a friendly voice on a platform your whole company already trusts by default.

The real lesson isn't "don't answer Teams calls" — it's that trust in internal-looking communication channels is now an attack surface in its own right. If your org verifies external emails but waves through anyone who shows up in a Teams call with an IT-sounding display name, you've built a very expensive lock on a door with the window left open next to it.

Seventeen hours from "hi, I'm from IT" to full encryption is a brutal reminder that your weakest link isn't your code, it's whoever picks up the phone.

Source: BleepingComputer