Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access
ID: 443a4ed4-47a0-5ff5-a1ac-eafc45022a3c
STIX ID: report--443a4ed4-47a0-5ff5-a1ac-eafc45022a3c
Feed Name: cybersecurityNews.com
Threat Score
BlueVoyant reports an ongoing social-engineering campaign where attackers impersonate IT support over Microsoft Teams and convince victims to use Quick Assist, then deploy digitally signed MSI installers that perform DLL sideloading to install a memory-resident backdoor named A0Backdoor which uses covert DNS MX lookups for command-and-control; the activity ties to prior Storm-1811/Black Basta operations and employs sophisticated anti-analysis and evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
