HIGH
Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Deployment
Threat actors are impersonating IT support staff in Microsoft Teams voice calls to trick employees into granting remote access to corporate devices. Once inside, the attackers deploy Chaos ransomware, according to BleepingComputer.
The campaign is targeting North American organizations. Security teams should treat unsolicited Teams calls claiming to be IT support as a potential vishing vector and verify identity through a separate channel before granting remote access.