Microsoft and Sophos reported separate but closely aligned social-engineering campaigns in which attackers impersonated IT support staff over Microsoft Teams, phone calls, and related pretexts to trick employees into granting remote access through Quick Assist or other support tools. Microsoft attributed its activity to Storm-1811, which used vishing and email-bombing to gain access, steal credentials through EvilProxy, and deploy tools including Qakbot, Cobalt Strike, ScreenConnect, NetSupport Manager, OpenSSH tunneling, and SystemBC before rolling out Black Basta ransomware with PsExec. Microsoft said it suspended malicious Teams accounts and tenants involved in the impersonation activity and added stronger Quick Assist warnings and trust indicators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Gurucul released technical details on the STAC4749 Microsoft Teams vishing campaign, including malicious domains, URLs, IP addresses, file hashes, and detection queries for hunting related activity. The report also described the attackers' use of a custom loader, backdoor, and modular post-exploitation tooling before Chaos ransomware deployment.
Expel reported first observing the newly observed MiniShai Hulud worm in May 2026, describing it as targeting the npm and PyPI ecosystems. The worm drove a spike in cloud supply chain incidents that month and was said to resemble, but not be connected to, the original Shai Hulud attack.
Sophos observed that at least three STAC4749 intrusions culminated in Chaos ransomware deployment, including one case that progressed from initial access to encryption in under 17 hours.
Sophos reported that a Microsoft Teams voice phishing campaign tracked as STAC4749 targeted dozens of organizations in Canada and the United States between February and June 2026 by impersonating IT support staff and persuading users to grant remote access.
Orange Cyberdefense said it observed a series of social-engineering attacks in December 2024 that began with email bombing and then shifted to Microsoft Teams outreach from accounts impersonating IT or help desk staff. In early December, it linked multiple incidents involving DarkGate and Lumma Stealer to the broader campaign and noted tradecraft overlaps historically associated with Black Basta operators.
Rapid7 said a Black Basta-linked social-engineering campaign resurfaced in early October 2024, using email bombing followed by Microsoft Teams impersonation to push Quick Assist, AnyDesk, TeamViewer, ScreenConnect, Level, or OpenSSH-based access. The report also documented updated credential-harvesting and payload delivery tradecraft, including a rundll32-launched DLL harvester and follow-on Zbot/Zloader or DarkGate malware.
Microsoft said it suspended malicious Teams accounts and tenants involved in the impersonation activity and was improving Quick Assist warnings and trust transparency in response to the campaign.
By late May 2024, Storm-1811 had expanded its social engineering activity to Microsoft Teams messages and calls impersonating help desk or IT staff to trick users into granting remote access.
Rapid7 reported that since late April 2024, attackers had targeted multiple MDR customers with email bombing followed by phone calls impersonating internal IT staff to obtain remote access via AnyDesk or Windows Quick Assist. After access, the actor used batch scripts, renamed OpenSSH components, registry Run-key persistence, credential harvesting, and in some cases attempted NetSupport, ScreenConnect, SMB lateral movement, and Cobalt Strike deployment; Rapid7 assessed the activity as consistent with Black Basta operators.
Microsoft Threat Intelligence reported that the financially motivated group Storm-1811 had been abusing Quick Assist since mid-April 2024 as part of intrusion chains that led to credential theft, malware delivery, and follow-on Black Basta ransomware activity.
Trend Micro reported a social-engineering intrusion in which attackers used Microsoft Teams voice phishing while impersonating support personnel to gain access and facilitate DarkGate malware deployment. The report documented Teams-based vishing as an intrusion vector tied to DarkGate activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
expel.com
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcerapid7.com
Open sourcemicrosoft.com
Open sourcerapid7.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.