logo

New Vishing Attack Leverages Microsoft Teams Call and QuickAssist to Deploy .NET Malware

ID: 634ad6b8-1c0d-508c-baa1-be95f393834f

STIX ID: report--634ad6b8-1c0d-508c-baa1-be95f393834f

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated vishing campaign leverages spoofed Microsoft Teams calls and Windows QuickAssist to socially engineer victims into executing a .NET Core 8.0 "updater.exe" that loads loader.dll, retrieves keys from jysync.info, downloads and decrypts a payload in memory (fileless execution) and redirects victims to domains such as ciscocyber.com, enabling stealthy C2 communications and evasion of traditional detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.