Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console

Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console

First seen 29 Jul 2026, 02:49 UTC Sophoswww.okta.comblog.talosintelligence.comwww.microsoft.com 84% similarity 69.5

Article Content

Browse articles
ThreatCluster

A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset, including a custom loader and backdoor, leading to subsequent ransomware deployment. Concurrently, Okta's Threat Intelligence revealed insights into Work Panel, a vishing operator console facilitating account takeovers through streamlined phishing operations. This multi-tenant platform allows rapid campaign launches and employs a structured workforce with distinct roles. The campaigns reflect a growing trend in vishing tactics, with significant impacts across various sectors, particularly in the U.S. and Canada.

Key Points: • STAC4749 vishing campaign targeted North American organizations using Microsoft Teams. • Work Panel enables rapid deployment of vishing operations with distinct roles for operators. • The campaigns have led to ransomware deployments and indicate a rise in vishing tactics.

ThreatCluster AI How this analysis works

Timeline

2026-02-01
STAC4749 campaign begins
Threat actors started targeting organizations in North America using Teams for vishing.
Sophos
2026-06-30
STAC4749 campaign ends
The campaign concluded with multiple organizations affected and ransomware deployed.
Sophos
2026-07-29
Okta reveals Work Panel insights
Okta's Threat Intelligence published findings on Work Panel, a console for vishing operations.
Okta

Community

Browse all →