Actor Profile
Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate. The malware is deployed by financially motivated operators who either directly conduct attacks or coordinate with affiliates. Sophos tracks the specific vishing campaign deploying Chaos as STAC4749, which targeted dozens of North American organizations between February and June 2026, with at least three intrusions resulting in ransomware deployment. The operation demonstrates sophisticated social engineering capabilities combined with rapid attack execution, achieving full compromise in as little as 17 hours from initial contact.
TTPs (Tactics, Techniques, Procedures)
Initial access is achieved through social engineering via Microsoft Teams voice calls and chats, where attackers impersonate IT support staff using external accounts registered on IT-themed .top domains (T1566.002 Phishing: Spearphishing Link, T1598 Phishing for Information). Attackers convince victims to install remote access tools including Microsoft Quick Assist and RemSupp (T1219 Remote Access Software). Post-compromise, PowerShell is used to download backdoors into %AppData% folders (T1059.001 PowerShell, T1105 Ingress Tool Transfer). Persistence is established via registry modifications disguised as legitimate Realtek and Windows audio components (T1547.001 Boot or Logon Autostart Execution: Registry Run Keys). Additional remote access tools like DWAgent and AnyDesk are installed for backup access (T1219). Remote Desktop Protocol is enabled for lateral movement (T1021.001 Remote Desktop Protocol). Data exfiltration occurs before ransomware deployment (T1041 Exfiltration Over C2 Channel). Finally, Chaos ransomware is deployed simultaneously across compromised devices with encryption and ransom note creation (T1486 Data Encrypted for Impact, T1491 Defacement).
Targets & Patterns
The STAC4749 campaign targeted North American organizations, with approximately 95% of attacks concentrated in Canada (50%) and the United States (45%). Victims span multiple sectors including services, manufacturing, energy, construction, engineering, technology, and corporate/enterprise environments. The targeting pattern suggests opportunistic selection rather than sector-specific focus, consistent with financially motivated ransomware operations. The attackers specifically targeted employees who could be socially engineered into granting remote access, focusing on individuals likely to respond to IT support impersonation. The rapid attack timeline (under 17 hours in one case) and simultaneous encryption across devices indicates the operators prioritize speed and impact to maximize ransom payment likelihood.
Historical Context
Chaos ransomware emerged as a RaaS operation in February 2025 and is linked to former members of BlackSuit and Royal ransomware gangs, both of which descended from the Conti cybercrime syndicate. This lineage places Chaos within the broader ecosystem of post-Conti operations that fragmented following Conti's dissolution. The STAC4749 vishing campaign builds on previous Microsoft Teams social engineering tactics observed in other operations. In October 2024, Black Basta affiliates used similar Teams-based impersonation techniques, flooding inboxes before contacting victims. More recently, the Iranian state-sponsored group MuddyWater allegedly used Chaos ransomware as a decoy in cyberespionage operations, though Sophos found no evidence connecting STAC4749 to MuddyWater. The STAC4749 campaign evolved its techniques between February and May 2026, continuously modifying malware filenames, persistence mechanisms, and deployment methods to evade detection. The shift from Microsoft Quick Assist to RemSupp in April 2026 demonstrates adaptive behavior in response to defensive measures.
Defensive Recommendations
- Configure Microsoft Teams to block external access or require approval for external communications, preventing unsolicited contact from threat actors using .top domains and other suspicious tenants (T1566.002 mitigation)
- Monitor and alert on PowerShell execution from user profiles, particularly downloads to %AppData% folders, using EDR or Sysmon Event ID 1 and 4104 for script block logging (T1059.001 detection)
- Implement application allowlisting to block unauthorized remote access tools such as RemSupp, DWAgent, and AnyDesk, while restricting Microsoft Quick Assist to authorized IT personnel only (T1219 mitigation)
- Detect suspicious registry modifications in Run keys, especially those masquerading as audio components (Realtek, WinAudio), through registry monitoring tools and SIEM correlation (T1547.001 detection)
- Monitor for unauthorized RDP enablement and lateral movement attempts via network traffic analysis and Windows Event ID 4624 (logon type 10) combined with anomalous source/destination patterns (T1021.001 detection)
---
# Geopolitical Context
Geopolitical Context
The STAC4749 campaign represents an evolution in social engineering tactics targeting North American corporate infrastructure, leveraging trusted collaboration platforms to bypass technical controls. The use of Microsoft Teams as an initial access vector reflects threat actors' adaptation to hybrid work environments where remote support interactions have become normalized. The campaign's focus on critical sectors—including energy, manufacturing, and construction—suggests potential economic disruption objectives beyond immediate financial gain. The rapid attack tempo (sub-17-hour compromise-to-encryption cycles) indicates operational sophistication consistent with organized cybercrime groups rather than opportunistic actors. The Chaos ransomware operation's reported lineage from BlackSuit, Royal, and ultimately the Conti syndicate places this activity within a broader ecosystem of post-Conti fragmentation, where experienced operators have dispersed into multiple successor groups while maintaining similar tactics and infrastructure.
State Actor Alignment
Sophos explicitly states no evidence connects STAC4749 to the Iranian state-sponsored MuddyWater group, despite both having deployed Chaos ransomware in separate campaigns. The MuddyWater operation appears to have used Chaos as a decoy for espionage objectives, whereas STAC4749 is assessed with high confidence as financially motivated. The campaign's targeting pattern—95% focused on U.S. and Canadian organizations across commercial sectors—is consistent with profit-driven cybercrime rather than state-directed intelligence collection or strategic disruption. The operational lineage to Conti-affiliated groups (BlackSuit, Royal) suggests Russian-speaking cybercriminal networks, though no direct state sponsorship is indicated. This distinction is significant: while Conti historically demonstrated ideological alignment with Russian state interests during the Ukraine conflict, successor operations like Chaos appear to operate as independent criminal enterprises without evidence of tasking or coordination from state actors.
Business Impacty pro region
The campaign's concentration on North American targets (50% Canada, 45% United States) creates localized economic risk for organizations in both countries, particularly in sectors critical to bilateral trade and energy security. The targeting of manufacturing, energy, and construction firms could have cascading supply chain effects given the integrated nature of U.S.-Canadian industrial operations. For European organizations, the campaign demonstrates the continued evolution of social engineering techniques that exploit remote collaboration tools now ubiquitous across transatlantic business operations. The use of Microsoft Teams—a platform with global enterprise adoption—suggests tactics proven in North America may be adapted for European targets. The sub-day attack tempo observed in STAC4749 incidents challenges incident response assumptions in both North American and European cybersecurity frameworks, which typically assume longer dwell times for ransomware operators. The campaign also highlights regulatory gaps: the use of ".top" domains for malicious infrastructure and cloud-based remote management tools (RemSupp) demonstrates how threat actors exploit loosely governed digital services that operate across jurisdictions.
Forecast
If Microsoft does not implement stricter controls on external Teams communications—such as enhanced verification for IT support personas or behavioral analytics for rapid remote access tool deployment—similar vishing campaigns are likely to proliferate across other regions and sectors. The attackers' demonstrated ability to iterate tactics monthly (changing malware filenames, persistence mechanisms, and deployment methods) suggests that if current detection methods prove effective, STAC4749 operators will likely shift to alternative collaboration platforms or communication vectors. Should Chaos ransomware continue to attract both financially motivated actors (STAC4749) and state-sponsored groups (MuddyWater) as reported, attribution complexity will increase, potentially delaying coordinated law enforcement responses. If the sub-17-hour attack cycle becomes standard among Conti successor groups, organizations without 24/7 security operations capabilities may face higher encryption rates before incident response can mobilize. The campaign's success in North America may encourage other cybercrime groups to adopt similar Teams-based social engineering, particularly if RemSupp or similar cloud RMM tools remain under-monitored in corporate environments.
