New Vishing Attack Leverages Microsoft Teams Call and QuickAssist to Deploy .NET Malware
ID: 634ad6b8-1c0d-508c-baa1-be95f393834f
STIX ID: report--634ad6b8-1c0d-508c-baa1-be95f393834f
Feed Name: cybersecurityNews.com
Threat Score
A sophisticated vishing campaign leverages spoofed Microsoft Teams calls and Windows QuickAssist to socially engineer victims into executing a .NET Core 8.0 "updater.exe" that loads loader.dll, retrieves keys from jysync.info, downloads and decrypts a payload in memory (fileless execution) and redirects victims to domains such as ciscocyber.com, enabling stealthy C2 communications and evasion of traditional detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
