Chaos Ransomware Now Hijacking Microsoft Teams Calls To Strike
By 813 Staff
Industry analysts are weighing in after Chaos Ransomware Now Hijacking Microsoft Teams Calls To Strike, according to BleepingComputer (@BleepinComputer) (in the last 24 hours).
Source: https://x.com/BleepinComputer/status/2082857952826835121
Marcus Hutchins, the security researcher who famously stopped WannaCry, has spent the last 48 hours dissecting a new attack chain that pairs old-school social engineering with a relatively new ransomware family. According to a report from @BleepinComputer, Microsoft Teams vishing campaigns are now being used to deploy Chaos ransomware, and the early findings suggest this is not the work of an amateur crew.
The attack begins with a phone call, not a phishing email. Threat actors are posing as IT support personnel and calling targets through Microsoft Teams, claiming there is a critical security issue with their account. Once the victim is on the line, the attacker walks them through a series of steps that ultimately lead to the installation of a remote management tool. Internal documents show that Microsoft has been tracking these lures for several weeks, but the pivot to Chaos ransomware marks a significant escalation in the campaign’s endgame.
Engineers close to the project say the attackers are abusing legitimate Teams features to bypass email security entirely, which makes the initial contact far more convincing than a typical spam message. The vishing angle is particularly nasty because it weaponizes the victim’s trust in a familiar corporate tool. After gaining remote access, the operators deploy Chaos — a ransomware strain that has been circulating in underground forums but has rarely been seen in enterprise-focused intrusions until now.
The rollout has been anything but smooth for the defenders. Chaos is notable for its lack of a proper encryption routine in some variants, and multiple samples have been flagged as broken or inefficient. But that has not stopped the operators from using it to lock down small and mid-sized businesses that lack robust incident response plans. The report indicates that the campaign appears to be opportunistic, targeting organizations that have Teams enabled and publicly listed employee directories, which makes it easier to identify potential victims for the initial phone call.
What remains uncertain is whether this is a one-off operation or a new playbook being sold to other affiliates. The BleepingComputer report notes that the malware’s command-and-control infrastructure is still active, suggesting the operators are not done yet. For IT teams, the immediate takeaway is blunt: verify any unsolicited support call through a secondary channel, and consider disabling external Teams calls if they are not strictly necessary. Microsoft has not yet issued a public advisory addressing this specific vector, but expect that to change as more victims come forward.
Source: https://x.com/BleepinComputer/status/2082857952826835121
