WorkThe story, in brief

Microsoft Teams vishing attacks lead to Chaos ransomware attacks - BleepingComputer

Hackers are now using Microsoft Teams itself as the vector for ransomware attacks—posing as IT support to deploy RMM tools and trigger Chaos ransomware deployments.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A real-world attack pattern (Operation BlueDash) shows how mainstream workplace tools become attack surface; practitioners need to audit Teams access controls and train staff on vishing tactics targeting internal IT personas.

The key facts

9 to know
  1. Operation BlueDash uses fake Teams updates and vishing (voice phishing) to impersonate IT support

  2. Attack deploys Level RMM and ScreenConnect remote-access tools as beachhead for Chaos ransomware

  3. Multi-RMM phishing technique suggests sophistication; targets enterprise Teams users

  4. Threat reported by Sophos, Hacker News, Cybersecurity Dive, SOC Prime (credible security sources)

  5. Operation BlueDash uses fake Teams update messages to initiate vishing attacks

  6. Campaign delivers Level RMM and ScreenConnect for lateral movement and ransomware deployment

  7. Attack vector: social engineering via Teams (not a model, capability, or AI system vulnerability)

  8. Multiple security vendors reporting (Sophos, The Hacker News, SOC Prime, Cybersecurity Dive)

  9. Published: July 30, 2026

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer Chaos in Teams vishing Sophos Hackers abuse Microsoft Teams in ransomware campaign through fake IT support Cybersecurity Dive Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work