logo

Hackers Hijack Microsoft Teams Accounts to Spread ModeloRAT Malware

ID: ab245d1e-0082-5ccb-8cd0-e7e6d057c207

STIX ID: report--ab245d1e-0082-5ccb-8cd0-e7e6d057c207

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Mayura Kathir

...
...

Hackers are abusing hijacked Microsoft Teams accounts and fake IT helpdesk chats to deliver an undocumented Python‑based ModeloRAT. The attack uses an obfuscated PowerShell command that writes and extracts a ZIP into %APPDATA% (creating a portable WinPython environment), launches pythonw.exe to run separate reconnaissance and C2 components, contacts hard‑coded IP-based C2 endpoints, and achieves persistence via a HKCU Run key plus a randomly named scheduled task; the variant evaded several EDR products and had zero VirusTotal detections at the time of analysis. Defenders are advised to tighten Teams external access, monitor cloud‑storage downloads and ZIP extraction under %APPDATA%, baseline pythonw.exe usage, and hunt for Run‑key and scheduled task indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.