Key Takeaways
- Attackers combined email bombing with fake Microsoft Teams support calls to establish remote access.
- Custom malware and legitimate administration tools helped prepare compromised environments for Chaos ransomware.
- Identity controls, application restrictions, and verification procedures can reduce exposure to these cross-channel attacks.
An employee’s inbox suddenly fills with unwanted messages. Soon afterward, a helpful technician calls through Microsoft Teams and offers to fix the problem. The timing makes the request seem credible, but both events are part of the same intrusion.
Sophos has traced that playbook to campaigns designed to establish remote access and ultimately facilitate deployment of Chaos ransomware. The activity blends Microsoft Teams vishing, custom malware, impersonated technical support, and remote administration tools. Rather than depending on one malicious attachment, attackers guide employees through several seemingly reasonable actions.
The initial email flood creates confusion and urgency. Attackers can then contact a target through Teams while posing as internal IT staff or an external support provider. That shift between channels matters. Employees who have learned to question unexpected email links may still place greater trust in a voice call appearing inside a collaboration service used throughout the workday.
According to Help Net Security, incident responders previously identified more than 15 incidents during a three-month period in which attackers paired email bombing with fraudulent Teams support calls. The callers sought remote access that could later support ransomware deployment.
Microsoft Teams carries the social context of work, distinguishing it from standard email inboxes. Names, profile images, meeting prompts, and support conversations can make an attacker’s approach feel routine, particularly when cross-tenant communication or permissive external access allows an unfamiliar account to make contact.
The volume of these campaigns is substantial. Cybersecurity News reported Microsoft’s detection of approximately 7.6 billion email-based phishing threats between April and June 2026. Teams phishing detections rose 19% from March to April and increased another 10% in June. Malicious voice-based call attempts grew about 80% from the beginning of 2026 and reached nearly 10 times their mid-2025 baseline.
Social engineering bypasses the need to develop complicated software exploits by simply persuading an employee to approve access. This calculation helps explain why compromised identities are becoming central to ransomware operations. Sophos’ 2026 Active Adversary Report found that 67.32% of investigated incidents began with a compromised identity.
Once inside, operators can introduce custom malware while also using legitimate remote-support products. Microsoft Quick Assist and similar utilities present a particular monitoring challenge because they have valid administrative purposes. Their presence alone does not prove malicious activity. The warning signs often come from context: an unsolicited support call, a new external Teams contact, unusual authentication activity, or remote-control software launched outside an approved support process.
A CyberProof review of cross-tenant Teams attacks in the first half of 2026 also highlights how collaboration features can become part of a broader social-engineering chain. For security teams, treating email, identity, voice, and endpoint telemetry as separate queues may leave that chain fragmented.
Defenses should therefore address both human verification and technical access. Phishing-resistant multifactor authentication can make stolen credentials less useful, though it does not prevent an employee from granting remote control during a convincing call. Organizations can also restrict unapproved remote-access applications, review external Teams communication policies, and require employees to verify support requests through a known internal channel.
Security awareness training works better when it reflects actual operational scenarios rather than generic warnings. Employees need to recognize that an email flood followed by an unsolicited Teams call may itself be an active incident.
Security operations teams can reinforce that lesson with alerts connecting sudden mailbox activity, external collaboration requests, remote-support launches, and unusual account behavior. None of those signals is conclusive by itself. Together, they can provide the early warning needed to interrupt access before custom malware and Chaos ransomware reach the deployment stage.
⬇️