Attack Times Are Shortening, Requiring Response Times To Match

According to reports, dozens of companies across the U.S. and Canada have been targeted by malware that utilizes Microsoft Teams.

Threat group STAC4749 has been initiating chats or calls via Microsoft Teams. Their communications attempt to trick victims by offering help desk or IT support.

A remote session is initiated through Microsoft Quick Assist or cloud-based RemSupp. The attackers then deploy PowerShell, which establishes persistence and executes malware.

In at least three cases involving this scheme, the attackers deployed Chaos ransomware into the compromised system.

In one case, the time from initial compromised access to ransomware deployment was 17 hours.

Targeted organizations were mainly in the industries of services, manufacturing, energy, construction, and engineering.

Source: https://www.cybersecuritydive.com/news/hackers-microsoft-teams-ransomware-it-support/826591/

Commentary

The above matter states that criminals are operating within a very short attack window, with only 17 hours passing between the initial contact to the malware deployment in one matter. Shorter windows give targets a much smaller window for their remediation efforts, especially those with slow response protocols.

Organizations must pre-plan their defense and detection strategies. In particular, they must tighten their standards to include lists of pre-approved and disallowed remote access tools. Any non-approved remote access tools should be prohibited. In addition, they must train on the risks associated with help desk and IT support scams.

The final takeaway is faster attacks require faster organizational responses. Work with your IT department to keep current on strategies for attack prevention.

Finally, your opinion is important to us. Please complete the opinion survey:

What's New

New Malware Threat Targeting Apple Devices Exploits Apple Notarization

A new malware threat uses a developer ID and poses as a legitimate Apple crash reporter to trick users. We examine how the malware works and what organizations that use macOS should do.

Using AI To Code Generates Higher Malware Risk: How Should Organizations Respond?

A recent study reveals significant malware risk exists associated with AI in coding. We examine the statistics and discuss the loss prevention options.

AI Malware May Be The New Hot Scam, But Don't Forget The Classics

AI has been getting much media attention in the cybersecurity sphere; however, the cyber attack basics are still legitimate risks, and they are not going away. We discuss those risks and what organizations need to know.

Latest Numbers

  • Unemployment Rate
    4.3% in Jan 2026
  • Payroll Employment
    +130,000(p) in Jan 2026
  • Average Hourly Earnings
    +$0.15(p) in Jan 2026
  • Employment Cost Index (ECI)
    +0.7% in 4th Qtr of 2025
  • Productivity
    +4.9% in 3rd Qtr of 2025

Source: Department of Labor