logo

Microsoft Teams Support Call Leads to Quick Assist Compromise in New Vishing Attack

ID: 9f7fe1b6-6568-5eb1-bb44-2f733765c6d7

STIX ID: report--9f7fe1b6-6568-5eb1-bb44-2f733765c6d7

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft DART investigated a November 2025 vishing campaign in which attackers impersonated IT via Microsoft Teams to trick a user into granting Quick Assist remote access, leading to credential theft through a spoofed portal and deployment of a malicious MSI that sideloaded a DLL to establish C2 and deliver encrypted loaders, remote execution, proxying, and session hijacking. The intrusion was short-lived and contained; DART recommended restricting inbound Teams communications from unmanaged accounts, auditing/disabling unnecessary RMM tools like Quick Assist, conducting vishing awareness training, and enabling conditional access and session anomaly detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.