STAC4749 is a financially motivated cybercriminal cluster associated with Microsoft Teams voice-phishing campaigns that targeted dozens of organizations in North America between February and June 2026. The operators impersonated IT helpdesk or support personnel in Teams chats and voice calls, using plausible employee-style identities and IT-themed cloud domains to persuade victims to approve remote support sessions through Microsoft Quick Assist or alternative remote-management tools such as RemSupp. The activity is notable for abusing trusted collaboration and remote-support workflows as an initial access vector. After obtaining remote access, STAC4749 conducted host and security-product discovery, established persistence, and expanded access within victim environments. Observed post-compromise tradecraft included PowerShell-based payload delivery, deployment of a custom loader, later transition to a Python-based backdoor, use of additional Golang implants, installation of secondary remote-access tools, reverse SOCKS proxying, and attempts to enable Remote Desktop Protocol for lateral movement. The group repeatedly changed filenames, persistence mechanisms, and deployment methods to evade signature-based detection. Persistence was achieved through user logon mechanisms including Run-key masquerading as audio-related components and Startup-folder shortcuts; at least one intrusion also involved experimentation with DLL sideloading. Multiple intrusions attributed to STAC4749 culminated in deployment of Chaos ransomware. In those cases, both data exfiltration and file encryption were observed, with at least one intrusion progressing from initial access to ransomware execution in under 17 hours. The operational pattern indicates either direct participation in Chaos ransomware deployment or close coordination with the Chaos ransomware ecosystem. Sophos assessed the cluster with high confidence as financially motivated. Reporting found no evidence supporting a link to MuddyWater; limited artifacts suggested a possible Russian-language connection, but attribution remained insufficient. STAC4749 has also been noted to share operational parallels with activity associated with Teams-based social engineering used to deploy Chaos ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
121 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster cited for operational parallels with the TWINLOOT campaign, particularly Teams voice phishing delivery, Python backdoors, reverse SOCKS5 proxying, and persistence mechanisms tied to Chaos ransomware deployment.
Cybercriminal campaign using Microsoft Teams chats and voice calls while impersonating helpdesk/IT staff to trick victims into approving remote access sessions, followed by discovery, RDP enablement, persistence, tunneling, and in some cases ransomware deployment.
Financially motivated cybercriminal cluster conducting Microsoft Teams vishing campaigns to gain remote access, followed by modular post-exploitation and, in several incidents, deployment of Chaos ransomware with data exfiltration and encryption.
A financially motivated intrusion cluster impersonating IT support staff in Microsoft Teams chats and calls to trick employees into launching remote support sessions, gain remote access, establish persistence, move laterally, and in multiple cases deploy Chaos ransomware against North American organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.