Threat Actors Use Hijacked Teams Accounts In ModeloRAT Attacks
ID: 6402b054-7a94-5715-a6a7-8d0492a4cc0c
STIX ID: report--6402b054-7a94-5715-a6a7-8d0492a4cc0c
Feed Name: Cyber Press
KongTuke is running a sophisticated campaign that uses hijacked or fake Microsoft Teams accounts to convince employees to run an obfuscated PowerShell downloader that retrieves a ZIP from Dropbox. The archive deploys a portable Python runtime and an evolved ModeloRAT that splits reconnaissance and C2 functionality, implements persistence (hidden registry keys and scheduled tasks), and has reportedly evaded enterprise endpoint detection; organizations are advised to restrict Teams external access, block unnecessary Dropbox downloads, and hunt for hidden AppData ZIP extraction and related activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
