Hackers Pose as IT Staff in Microsoft Teams to Install Malware
ID: d202ec09-b7bc-58f1-b7b2-15d3843e045d
STIX ID: report--d202ec09-b7bc-58f1-b7b2-15d3843e045d
Feed Name: TechRepublic Security
BlueVoyant researchers describe an ongoing campaign leveraging Microsoft Teams impersonation and Quick Assist social engineering to trick victims into running malicious MSI installers that sideload a fake hostfxr.dll loader; the loader decrypts and executes A0Backdoor, which fingerprints hosts and uses DNS MX-based tunneling to receive commands. The operation targets finance and healthcare, employs anti-analysis and time-window execution techniques, and is associated with the Blitz Brigantine/Storm-1811 cluster; recommended defenses include restricting remote-support tools, application allow-listing, DLL sideloading and DNS monitoring, and using EDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
