[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkjHytgu_Nu7xP9xhRMvWSCmw4PkuD_JdkWtQNptXLAE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"6fe04db2-ea12-4936-bc88-a02e7e342acd","fake-it-support-calls-on-teams-lead-to-ransomware-in-under-17-hours","7b674b25-eb6f-4528-acb0-dd1ab22eb1a0","Fake IT Support Calls on Teams Lead to Ransomware in Under 17 Hours","Attackers exploited employee trust in internal IT support by impersonating helpdesk staff over Microsoft Teams, convincing victims to hand over remote access via legitimate tools like Quick Assist. Once inside, they deployed backdoors disguised as trusted audio drivers before launching Chaos ransomware — all within 17 hours of initial contact. This attack succeeds not because of a software vulnerability, but because employees lacked the awareness and verification processes to distinguish real IT staff from impostors. The speed of compromise underscores how social engineering can bypass technical controls entirely, making human-layer defenses critical.","**Immediate actions:**\n- Establish and enforce a strict policy requiring employees to verify IT support identity through an official internal directory before granting any remote access.\n- Restrict or disable Microsoft Quick Assist and similar remote access tools for standard users, allowing use only via approved, audited channels.\n- Alert all staff to the active campaign with specific examples of what fake IT outreach looks like, including unsolicited Teams calls from unknown accounts.\n\n**Long-term improvements:**\n- Implement a verified IT support workflow where helpdesk staff initiate sessions only through ticketing systems, never via unsolicited calls.\n- Apply conditional access policies to block remote desktop tools from running unless explicitly authorized by a privileged account.\n- Regularly conduct vishing simulation exercises to measure and improve employee resistance to social engineering over voice and video channels.\n\n**Detection measures:**\n- Monitor and alert on the execution of remote access tools (Quick Assist, RemSupp) by non-IT user accounts in your SIEM or EDR platform.\n- Create detection rules for suspicious persistence mechanisms disguised as Realtek or Windows audio components in unexpected registry or startup locations.\n- Set up anomaly alerting for unusually rapid privilege escalation or lateral movement activity occurring within short post-login timeframes.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 14: Security Awareness and Skills Training","CIS Control 17: Incident Response Management","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 IR-4: Incident Handling","NIST SP 800-53 SI-4: System Monitoring","NIST CSF DE.CM-3: Personnel Activity Monitoring","MITRE ATT&CK T1219: Remote Access Software","MITRE ATT&CK T1566: Phishing (Vishing variant)","MITRE ATT&CK T1547: Boot or Logon Autostart Execution","published","2026-07-30T16:20:25.21518+00:00","2026-07-30T16:20:25.096+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmicrosoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks\u002F","microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks-364711","Microsoft Teams vishing attacks lead to Chaos ransomware attacks",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]