Microsoft Teams-Based Vishing Attack Tricks Victims Into Quick Assist Takeover
ID: 7fe33394-e53f-5da3-98ce-fa0d4c0cb939
STIX ID: report--7fe33394-e53f-5da3-98ce-fa0d4c0cb939
Feed Name: GBHackers
Microsoft’s DART investigated a November 2025 identity-first intrusion where threat actors used persistent vishing via Microsoft Teams to impersonate IT, obtain Quick Assist remote access, and direct a user to a spoofed site that harvested credentials and downloaded a malicious MSI that sideloaded a DLL for outbound C2 and session hijacking. The attackers expanded access using encrypted loaders and proxy-based connections but were rapidly contained by DART; forensic analysis found short-lived access with no persistence and no directory-level impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
