Chaos ransomware deployment in STAC4749 intrusions
Malware Activity
Summary
Hide ▲
Show ▼
The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft Teams vishing to gain remote access, then added backup remote tools to keep access to compromised systems. The malware’s rapid deployment and persistence increased the speed and reliability of the extortion operation across North American organizations.
Related Happenings
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Luxury jewelry retailer hit by ransomware attack
Incident
H score45
First: 07.07.2026 16:27
Last: 07.07.2026 16:27
Sources 1
About this happening:
A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Luxury jewelry retailer hit by ransomware attack
IncidentAbout this happening: A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor Meta
H score67
First: 03.07.2026 14:30
Last: 03.07.2026 14:30
Sources 1
About this happening:
Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor MetaAbout this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
MuddyWater’s Chaos masquerade shows state-backed espionage adopting ransomware tradecraft
Threat Actor Meta
H score23
First: 24.06.2026 15:00
Last: 24.06.2026 15:00
Sources 1
About this happening:
MuddyWater is using Chaos ransomware branding and criminal tradecraft to disguise state-backed espionage, making attribution and response harder across targeted enviro...
MuddyWater’s Chaos masquerade shows state-backed espionage adopting ransomware tradecraft
Threat Actor MetaAbout this happening: MuddyWater is using Chaos ransomware branding and criminal tradecraft to disguise state-backed espionage, making attribution and response harder across targeted enviro...
Timeline
-
30.07.2026 18:56 2 articles · 1h ago
Chaos ransomware deployment in STAC4749 intrusions
Initial DisclosureThe operation first used Microsoft Teams vishing to impersonate IT support and obtain remote access to employee devices. Early access was then converted into malware delivery and persistence before ransomware encryption began.
Show sources
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks — www.bleepingcomputer.com — 30.07.2026 18:56
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks — www.bleepingcomputer.com — 30.07.2026 18:56