Cybercriminals have found a new way around email filters and spam blockers: they're calling employees directly through Microsoft Teams. A recent campaign linked to Chaos ransomware shows attackers using voice phishing, or "vishing," inside Teams to trick workers into handing over network access, ultimately leading to ransomware deployment across corporate systems.

This isn't just another phishing email story. It's a sign that attackers are deliberately targeting the collaboration platforms millions of employees now trust by default, and it's forcing a rethink of how organizations train staff to spot social engineering.

How the Microsoft Teams Vishing Attack Works

Unlike traditional phishing, which relies on a malicious link or attachment sitting in an inbox, this attack style uses live voice contact. Attackers reach out to employees through Microsoft Teams, often posing as internal IT support or a trusted vendor, and use the call to build urgency and credibility. Because the interaction happens inside a platform employees already use daily for legitimate work requests, the psychological barrier that normally makes people suspicious of unsolicited emails simply isn't there.

Once trust is established, the attacker's goal is straightforward: get the target to take an action that grants remote access, whether that's approving a login prompt, installing a remote access tool, or sharing credentials under the guise of a support ticket. From there, the attacker has a foothold inside the corporate network, which sets the stage for the ransomware payload.

This approach mirrors a broader trend of attackers exploiting Microsoft 365 environments rather than attacking software vulnerabilities directly. It echoes tactics seen in the Storm-2949 campaign targeting Microsoft 365 password resets, where threat actors manipulated trusted cloud workflows instead of relying on malware alone to breach organizations.

Why Voice Phishing Bypasses Traditional Security Training

Most corporate security awareness programs are built around email: don't click unknown links, check the sender address, hover before you trust. Voice phishing sidesteps nearly all of that training because there's no email to scrutinize, no obviously spoofed domain, and no static message an employee can quietly forward to a security team for review.

A live phone or Teams call also introduces social pressure that email doesn't. A calm, professional-sounding voice claiming to be from IT support, especially one that references real internal terminology or recent company events, can push an employee toward quick compliance before they've had time to think critically. That combination of trusted platform, real-time pressure, and limited employee preparation is exactly why vishing has become an attractive entry point for ransomware operators.

What Chaos Ransomware Does Once Inside a Network

Once attackers have used the vishing call to establish access, the next stage is deploying Chaos ransomware. Like other ransomware families, Chaos is designed to move through a compromised network, encrypt files and systems, and hold that data hostage until a ransom is paid. The damage isn't limited to a single machine; ransomware operators typically try to spread as widely as possible within a network before triggering encryption, maximizing pressure on the victim organization to pay.

What makes this campaign notable is the delivery method rather than the ransomware itself. By gaining legitimate-looking access through a trusted communication channel, attackers can potentially skip past several layers of technical defenses that would normally flag suspicious downloads or unusual login attempts.

Defenses for Remote and Hybrid Workers: MFA, VPNs, and Voice Verification

For organizations with distributed or hybrid teams, this kind of attack is a reminder that identity verification needs to extend beyond email and login screens. A few practical steps can meaningfully reduce risk:

  • Require multi-factor authentication (MFA) for all remote access and sensitive systems, and train employees to never approve an MFA prompt they didn't personally initiate.
  • Establish a clear, company-wide policy for verifying IT support requests, such as requiring employees to call back a known internal number rather than trusting an inbound Teams call or message.
  • Use a VPN alongside strict access controls so that even if credentials are compromised, lateral movement across the network is harder to achieve.
  • Extend phishing awareness training to cover voice and chat-based social engineering, not just email.

What This Means For You

If you work in a hybrid or remote role and use Microsoft Teams regularly, treat unexpected calls or messages from "IT support" with the same skepticism you'd apply to a suspicious email. Legitimate IT departments rarely reach out cold through chat platforms asking you to install software or approve access requests on the spot. When in doubt, hang up, verify through an official channel, and report the interaction to your security team immediately.

Key Takeaways

The rise of Microsoft Teams vishing ransomware attacks shows that cybercriminals are adapting faster than many corporate training programs. As collaboration tools become the new frontline for social engineering, organizations need to update their defenses accordingly: strengthen MFA policies, formalize IT verification procedures, and make sure employees understand that trust in a platform doesn't equal trust in every person using it. Staying alert to unsolicited voice and chat requests, no matter how convincing they sound, remains one of the simplest and most effective ways to stop a ransomware attack before it starts.