Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services security alert graphic with a red warning triangle on a navy background

Sophos has published details of a campaign where attackers impersonate IT helpdesk staff on Microsoft Teams to trick employees into granting remote access — then deploy Chaos ransomware. In at least one case, the entire chain from first Teams call to encrypted files took under 17 hours.

The group, tracked as STAC4749, targeted dozens of organisations between February and June 2026. They register convincing domains like sequrityupdate.top and supportsoft.top, create Microsoft 365 tenants on those domains, then cold-call employees via Teams voice or chat. The calls are short — most under three minutes — and the ask is simple: open Quick Assist or install a remote support tool called RemSupp so “IT” can fix an issue. Once in, they drop backdoors disguised as Realtek audio drivers, move laterally via RDP, and in at least three confirmed cases, deployed Chaos ransomware.

Why This Matters for Australian Businesses

This attack works because Microsoft Teams allows external calls and messages by default. Most Australian SMBs we work with leave that setting enabled — they use Teams to talk with clients, suppliers, and contractors daily. That’s exactly the gap this campaign exploits. An employee sees an incoming Teams call from what looks like an IT support account, and the interface gives no obvious warning that the caller is from outside the organisation.

Hospitality venues running multiple sites, not-for-profits with lean IT oversight, and financial services firms handling sensitive client data are all exposed if external Teams access is wide open.

What to Do

  • Restrict external calling and messaging in the Microsoft Teams admin centre. If your business doesn’t need external voice calls, disable them. If you do, whitelist specific domains rather than allowing all.
  • Disable or restrict Quick Assist via Intune policy. It’s the primary tool attackers use to get in.
  • Brief your team: your real IT provider will never cold-call you on Teams asking you to install remote access software.
  • If someone has already granted access to an unexpected caller, disconnect immediately and contact your IT provider.

How All IT Can Help

We configure and manage Microsoft 365 tenants for businesses across Sydney, the Central West, and Brisbane — including the Teams external access policies that block this exact attack. If you’re not sure how your tenant is configured, get in touch and we’ll check it. Monthly contracts, no lock-in.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →

Posted in Security