logo

New Microsoft Teams Vishing Attack Exploits Quick Assist to Deploy Stealthy Malware

ID: 78f849b2-bc84-5ba2-802a-c45984b70d6c

STIX ID: report--78f849b2-bc84-5ba2-802a-c45984b70d6c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Do Son

...
...

A global, highly coordinated Microsoft Teams vishing campaign targets corporate employees (notably in the legal sector) by flooding inboxes and impersonating IT to get users to run Quick Assist and download a Java-based backdoor (Nimbus RAT); actors use Google Drive/Sheets for C2 and deploy a secondary OneDrive-based data-theft tool (InboxSetupPro) that exfiltrates messaging databases (e.g., Signal attachments) and large email archives, with researchers observing rapid compromise (under 20 minutes) and telemetry showing 1,540 similar events across 172 environments — activity linked to ransomware-affiliated criminal groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.