Phishing awareness training has spent a decade teaching people to distrust email. This campaign does not use email.

Sophos tracks it as STAC4749. Between February and June 2026 it targeted dozens of organisations, and the initial contact came through Microsoft Teams — external accounts impersonating IT helpdesk staff, opening a chat and then placing a voice call.

Why the channel is the attack

Teams occupies a different position in a user's head than an inbox does.

Email is where strangers arrive. Everybody knows this. Teams is where colleagues are — it is the internal tool, the one with the org chart behind it, and a message there carries an implicit assurance that whoever sent it belongs.

That assurance is mostly false. In a default configuration, external accounts can initiate contact with your staff. The interface does mark them, but a marker on an interface people use forty times a day is not the same as a warning anybody reads.

Add a voice call and the remaining friction disappears. A phishing email asks someone to click a link on their own. A voice call asks them to follow instructions from a person who is talking to them, who sounds like IT, who is waiting.

Sophos notes the operators used a consistent set of IT-themed cloud domains and personas — this was infrastructure built for the purpose, not opportunistic.

What happened after they were let in

Once remote access was granted, the operators deployed a modular post-exploitation toolset, including a custom loader and backdoor for persistent access.

Then a second step worth noting: they installed DWAgent or AnyDesk as backup access.

That is not a technical necessity — they already had a backdoor. It is an operational choice about resilience. Legitimate remote-support software is signed, often already present in enterprise estates, and frequently allowlisted precisely because IT uses it. If defenders find and remove the custom implant, the commercial tool survives, and it survives because it looks like something the organisation installed itself.

The 17-hour number

At least three of these intrusions ended in Chaos ransomware.

In one, the time from initial access to file encryption was under 17 hours.

That figure is the operational point of the whole article. Seventeen hours means one overnight. It means the detection happened, if it happened, while nobody was reading the alerts, and the response began the following morning against an environment that was already encrypted.

Playbooks written around a dwell time of days do not fit here. Neither does an escalation path that depends on someone noticing a ticket during business hours.

Who was hit

DimensionDetail
Geography~95% North America — Canada 50%, US 45%
SectorsServices, manufacturing, energy, construction and engineering
PeriodFebruary–June 2026
ScaleDozens of organisations

The sector list is worth reading carefully. Manufacturing, energy, construction and engineering are not industries with large security teams as a rule. They are industries with distributed sites, contractor-heavy workforces, and genuine reasons for an unfamiliar IT person to call — which is exactly the environment in which this pretext is plausible.

What to change

  • Restrict external Teams contact. Most organisations do not need arbitrary outside accounts initiating chats with staff. Where federation is genuinely required, allowlist the domains rather than permitting all.
  • Make the helpdesk verifiable in one direction only. Establish, and communicate, that IT never initiates a remote-access request over Teams — and give staff a number to call back on. A pretext survives on the target having no way to check.
  • Alert on remote-access tooling appearing. DWAgent and AnyDesk showing up on a machine that had neither should generate an alert regardless of signature or reputation. This is the highest-yield detection in the whole chain, precisely because the tools are legitimate.
  • Plan for overnight. If seventeen hours is achievable, out-of-hours coverage is not a maturity milestone, it is the difference between an incident and an outage.
  • Tell people the specific story. "Be careful of phishing" does not inoculate against this. "IT will never call you on Teams and ask for remote access, and if someone does, hang up and call this number" does.

The pattern underneath

Every element here is legitimate software behaving as designed. Teams allowing external contact. Voice calls. Commercial remote-support tools. Nothing was exploited.

What was attacked was the trust boundary a user carries in their head — the assumption that the internal tool contains internal people. That boundary is not enforced by the software, and no patch is coming for it.