logo

Voice Phishing on Microsoft Teams Facilitates DarkGate Malware Attack

ID: 594be5b1-328d-559e-8460-b866f4f95871

STIX ID: report--594be5b1-328d-559e-8460-b866f4f95871

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-12-17

Date Updated: 2026-04-22

Author: do son

...
...

Trend Micro analyzed a campaign in which attackers used voice phishing (vishing) via Microsoft Teams to convince a victim to install AnyDesk, gain remote access, and deploy DarkGate (Trojan.AutoIt.DARKGATE.D). The malware used an encrypted AutoIt payload (script.a3x), DLL sideloading, and process injection (e.g., MicrosoftEdgeUpdateCore.exe) to achieve persistence, evade detection, perform system discovery, execute commands, and communicate with a command-and-control server; Trend Micro warns organizations to combine technical controls with user education to mitigate this emerging vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.