Attackers Exploit Teams, Quick Assist to Deploy Stealthy A0Backdoor
ID: b86f08b6-ffa1-594b-8ac2-aef5c4f57fa5
STIX ID: report--b86f08b6-ffa1-594b-8ac2-aef5c4f57fa5
Feed Name: GBHackers
BlueVoyant reports an active, financially motivated intrusion campaign that lures victims with email bombing and Microsoft Teams IT‑support impersonation to obtain Quick Assist remote control, then installs digitally signed MSI packages that sideload a malicious hostfxr.dll. The DLL acts as a sophisticated loader for a new backdoor called A0Backdoor, which uses time‑gated decryption, sandbox detection, and DNS tunneling via MX records to public recursive resolvers for command‑and‑control; activity is linked with moderate‑to‑high confidence to Blitz Brigantine/Storm‑1811 associated with Black Basta and Cactus affiliates, and organizations are advised to tighten Teams/Quick Assist governance and monitor DNS/Microsoft personal content downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
