Threat actor STAC4749 conducted a Microsoft Teams voice phishing (vishing) campaign targeting North American organizations, impersonating IT support to gain remote access. After initial compromise, the attackers deployed a custom loader, backdoor, and modular post-exploitation tools to maintain persistence, enabling data exfiltration and the deployment of Chaos ransomware....