Similar Tradecraft Across Two Teams & Quick Assist Intrusions
ID: 8178a963-973a-5a03-ab81-9c8b03a8708e
STIX ID: report--8178a963-973a-5a03-ab81-9c8b03a8708e
Feed Name: Arctic Wolf Blog
Arctic Wolf observed two independent enterprise intrusions leveraging Microsoft Teams social engineering to induce Quick Assist remote sessions, after which attackers used PowerShell downloaders from cloud-hosted repositories to deploy multi-stage payloads (Rust reverse-SOCKS proxy, additional binaries, and a VLESS+Reality tunneling implant masquerading as Chrome/Adobe updaters) that establish persistent encrypted tunnels; the report details IOCs, behavioral detection rules, and defensive hardening (disable/secure Quick Assist, application control, PowerShell restrictions, MFA, egress controls, and user verification procedures).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
