Microsoft Teams vishing attacks lead to Chaos ransomware attacks - BleepingComputer
Hackers are now using Microsoft Teams itself as the vector for ransomware attacks—posing as IT support to deploy RMM tools and trigger Chaos ransomware deployments.

Why it matters
A real-world attack pattern (Operation BlueDash) shows how mainstream workplace tools become attack surface; practitioners need to audit Teams access controls and train staff on vishing tactics targeting internal IT personas.
The key facts
9 to knowOperation BlueDash uses fake Teams updates and vishing (voice phishing) to impersonate IT support
Attack deploys Level RMM and ScreenConnect remote-access tools as beachhead for Chaos ransomware
Multi-RMM phishing technique suggests sophistication; targets enterprise Teams users
Threat reported by Sophos, Hacker News, Cybersecurity Dive, SOC Prime (credible security sources)
Operation BlueDash uses fake Teams update messages to initiate vishing attacks
Campaign delivers Level RMM and ScreenConnect for lateral movement and ransomware deployment
Attack vector: social engineering via Teams (not a model, capability, or AI system vulnerability)
Multiple security vendors reporting (Sophos, The Hacker News, SOC Prime, Cybersecurity Dive)
Published: July 30, 2026
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer Chaos in Teams vishing Sophos Hackers abuse Microsoft Teams in ransomware campaign through fake IT support Cybersecurity Dive Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker…