STAC4749 is a financially motivated cybercriminal cluster tracked for a Microsoft Teams voice-phishing campaign active from February through June 2026. The operation targeted dozens of organizations in North America, with observed targeting concentrated in Canada and the United States. Reported victim sectors included services, manufacturing, energy, construction and engineering, and legal organizations focused on intellectual property services. The actor’s initial access tradecraft relied on impersonating helpdesk or IT support personnel in Microsoft Teams chats and voice calls, using plausible employee-style identities and IT-themed cloud domains to appear legitimate. Victims were socially engineered into approving remote support sessions through Microsoft Quick Assist or alternative remote-management tools. After access was obtained, the operators conducted host and security-product discovery, attempted to enable Remote Desktop Protocol for lateral movement, and used additional remote-access channels to maintain access. Post-compromise activity included deployment of a modular malware chain comprising a custom loader, a Python-based backdoor, and Golang implants, along with persistence mechanisms that were repeatedly modified to evade detection. The operators also used reverse SOCKS proxy capability and, in some intrusions, secondary remote administration tools for backup access. Sophisticated evasion behavior included frequent changes to filenames, persistence methods, and deployment workflows, as well as at least one observed experiment with DLL sideloading. Multiple STAC4749 intrusions culminated in deployment of Chaos ransomware. In those cases, both data exfiltration and encryption were observed or assessed, with one intrusion progressing from initial access to ransomware execution in under 17 hours. The activity is assessed as financially motivated and either directly tied to ransomware deployment or coordinated with actors in the Chaos ransomware ecosystem. No high-confidence state attribution is established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
121 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal campaign using Microsoft Teams chats and voice calls while impersonating helpdesk/IT staff to trick victims into approving remote access sessions, followed by discovery, RDP enablement, persistence, tunneling, and in some cases ransomware deployment.
Financially motivated cybercriminal cluster conducting Microsoft Teams vishing campaigns to gain remote access, followed by modular post-exploitation and, in several incidents, deployment of Chaos ransomware with data exfiltration and encryption.
A financially motivated intrusion cluster impersonating IT support staff in Microsoft Teams chats and calls to trick employees into launching remote support sessions, gain remote access, establish persistence, move laterally, and in multiple cases deploy Chaos ransomware against North American organizations.
Conducted a Microsoft Teams vishing campaign against North American organizations, impersonating IT support for initial access, then deploying a custom loader, backdoor, modular post-exploitation tooling, exfiltrating data, and ultimately deploying Chaos ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.