STAC4749 is a Sophos-tracked cybercriminal activity cluster associated with Microsoft Teams voice-phishing campaigns and linked to the Chaos ransomware ecosystem. The cluster was active at least from February through June 2026 and targeted dozens of organizations in North America, with observed targeting concentrated in Canada and the United States. Sophos assessed the operation as financially motivated and found that multiple intrusions culminated in deployment of Chaos ransomware, including cases involving both data theft and encryption. STAC4749 commonly impersonates helpdesk or IT support personnel in Microsoft Teams chats and voice calls, using plausible employee-style identities and IT-themed cloud domains to persuade users to approve remote-support sessions. The operators initially favored Microsoft Quick Assist and also used alternative remote-management tools when needed. After obtaining remote access, they conducted host and security-product discovery, attempted to enable Remote Desktop Protocol for broader access, and deployed a modular malware chain that evolved over time. Observed tooling included a custom loader, a persistent Python-based backdoor, Golang implants, secondary remote-access channels, and a reverse SOCKS proxy used to communicate with internal systems and support lateral movement. The cluster demonstrated persistent adaptation in filenames, persistence mechanisms, and deployment methods to evade detection and improve reliability. Persistence was established through user-level autorun mechanisms, including Run-key abuse and Startup-folder shortcuts disguised as benign audio or system components. In at least one intrusion, the actors experimented with DLL sideloading. Sophos observed rapid operational tempo, including one case that progressed from initial access to ransomware deployment in under 17 hours. Known aliases are limited to the cluster designation STAC4749. Reporting has noted operational parallels between STAC4749 and later Teams-based intrusions involving PyArmor-protected Python backdoors and reverse SOCKS functionality, but current evidence supports describing STAC4749 as a distinct activity cluster rather than conclusively merging it with another named actor. Overall, STAC4749 is best characterized as a financially motivated intrusion cluster using Teams-based social engineering, legitimate remote-support tooling, custom malware, persistence, lateral movement, exfiltration, and ransomware deployment in support of Chaos-related extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
125 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possibly related cybercriminal cluster with significant overlaps in Teams vishing, PyArmor-protected Python backdoor usage, reverse SOCKS5, and persistence patterns, but described as operationally distinct from the TWINLOOT activity.
Activity cluster cited for operational parallels with the TWINLOOT campaign, particularly Teams voice phishing delivery, Python backdoors, reverse SOCKS5 proxying, and persistence mechanisms tied to Chaos ransomware deployment.
Activity cluster linked in the content to Chaos RaaS and compared to TWINLOOT due to similar Teams vishing delivery, PyArmor-obfuscated Python backdoor use, reverse SOCKS proxying, and persistence patterns.
Cybercriminal campaign using Microsoft Teams chats and voice calls while impersonating helpdesk/IT staff to trick victims into approving remote access sessions, followed by discovery, RDP enablement, persistence, tunneling, and in some cases ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.