HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Vishing Attacks via Microsoft Teams Enable Chaos Ransomware Deployments Across North America

Threat actors impersonated IT support in Microsoft Teams calls, used Quick Assist or RemSupp to gain remote access, and deployed Chaos ransomware that encrypted files within hours. The incident underscores the need for robust SOC 2 access‑control policies and security‑awareness training.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
bleepingcomputer.com

Vishing Attacks via Microsoft Teams Enable Chaos Ransomware Deployments Across North America

What Happened — Threat actors impersonated IT support staff in Microsoft Teams voice and chat sessions, convincing users to launch remote‑support tools (Quick Assist or the third‑party RemSupp). Within minutes they gained a foothold, deployed PowerShell backdoors, and in at least three cases unleashed Chaos ransomware that encrypted files in under 17 hours.

Why It Matters for Compliance & Audit Readiness

  • The campaign exploits weak access‑control and remote‑session policies—exactly the controls SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) are designed to protect.
  • Continuous evidence of security‑awareness training and remote‑access monitoring is required to demonstrate due diligence during a SOC 2 audit.

Who Is Affected – Organizations in services, manufacturing, energy, construction/engineering, and other North‑American sectors that use Microsoft Teams for collaboration.

Recommended Actions

  • Map remote‑access and remote‑support tooling to SOC 2 access‑control requirements; enforce MFA and least‑privilege for any remote‑session utilities.
  • Conduct targeted security‑awareness training on vishing and “IT‑support” impersonation scenarios; log and review all Quick Assist/RemSupp sessions for anomalous activity.

Technical Notes – Attack vector: vishing (voice phishing) → stolen credentials → remote‑access tools (Quick Assist, RemSupp). No public CVE; attackers used “.top” domains (e.g., sequrityupdate.top) to host fake support sites. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →