Microsoft Teams Vishing Spreads DarkGate RAT
ID: 299fbd08-2f2d-5d60-8210-bbe082d5306c
STIX ID: report--299fbd08-2f2d-5d60-8210-bbe082d5306c
Feed Name: Dark Reading
Date Published: 2024-12-16
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers observed a multistage vishing campaign in which attackers used a Microsoft Teams voice call and social engineering to persuade a user to install AnyDesk after a Microsoft Remote Support install failed; the adversary then established a C2 channel and deployed DarkGate via an AutoIt-based dropper. DarkGate provides remote control, credential theft, keylogging, RDP/AnyDesk abuse, persistence, and can deliver additional payloads; the infection was halted before data exfiltration. The report highlights vishing as an emerging delivery vector and recommends employee training, vendor verification, whitelisting remote-access tools, and MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
