Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

Sophos tracks the campaign as STAC4749 and says it targeted dozens of organizations between February and June 2026.

At least three of these intrusions led to the deployment of Chaos ransomware, with one attack going from initial access to encrypting files in less than 17 hours.

Sophos says about 95% of the attacks targeted organizations in Canada (50%) and the United States (45%).

The threat actors targeted organizations across numerous sectors, with services, manufacturing, energy, and construction and engineering experiencing the largest number of attacks.