CybersecurityJuly 30, 2026· via BleepingComputer

Microsoft Teams vishing scams pave the way for ransomware

Microsoft Teams vishing scams pave the way for ransomware

Image : BleepingComputer

A new wave of vishing attacks is hijacking Microsoft Teams to bypass security and drop Chaos ransomware inside North American companies. Attackers pose as IT support staff in unsolicited video calls, lure victims into granting remote access, and then deploy file-encrypting malware under the guise of “routine maintenance.” Once inside, the threat actors encrypt systems and demand payment to restore operations—highlighting how legitimate collaboration tools can be weaponized.

A twist on classic vishing

Security teams have long warned about voice-based impersonation, but this campaign takes it a step further by using Microsoft Teams’ real-time video and screen-sharing capabilities. Victims receive a call from an account that appears to belong to their own IT department, often outside regular business hours when defenses are lower. The attackers use social engineering to convince the target to install remote-desktop software or grant permissions, then pivot to deploying Chaos ransomware across the network.

Why it matters

This tactic shifts the attack surface from phishing emails to the tools employees use daily, making defenses harder to enforce. Organizations that rely on Microsoft Teams for internal communication must now scrutinize every unsolicited call, even if the caller ID looks familiar. Beyond immediate ransomware risks, the breach of trust in internal tools could erode employee confidence and complicate incident response. A single misstep can cascade into operational downtime, regulatory fines, and reputational damage—underscoring the need for layered identity verification and user training that extends to collaboration platforms.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home