Chaos ransomware deployment in STAC4749 intrusions
Malware Activity
Summary
Hide ▲
Show ▼
The Chaos ransomware activity was deployed in at least three intrusions, including one case that reached file encryption in under 17 hours. Attackers used Microsoft Teams vishing to gain remote access, then added backup remote tools to keep access to compromised systems. The malware’s rapid deployment and persistence increased the speed and reliability of the extortion operation across North American organizations.
Related Happenings
StormEncryptor ransomware deployment by Storm-1175
Malware Activity
H score40
First: 10.08.2026 20:42
Last: 10.08.2026 20:42
Sources 1
About this happening:
Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
StormEncryptor ransomware deployment by Storm-1175
Malware ActivityAbout this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Luxury jewelry retailer hit by ransomware attack
Incident
H score45
First: 07.07.2026 16:27
Last: 07.07.2026 16:27
Sources 1
About this happening:
A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Luxury jewelry retailer hit by ransomware attack
IncidentAbout this happening: A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor Meta
H score67
First: 03.07.2026 14:30
Last: 03.07.2026 14:30
Sources 1
About this happening:
Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance
Threat Actor MetaAbout this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...
Timeline
-
30.07.2026 18:56 2 articles · 13d ago
Chaos ransomware deployment in STAC4749 intrusions
Initial DisclosureThe operation first used Microsoft Teams vishing to impersonate IT support and obtain remote access to employee devices. Early access was then converted into malware delivery and persistence before ransomware encryption began.
Show sources
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks — www.bleepingcomputer.com — 30.07.2026 18:56
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks — www.bleepingcomputer.com — 30.07.2026 18:56