logo

Threat actors misusing Quick Assist in social engineering attacks leading to ransomware

ID: 17a34df4-d8a7-5363-8db1-df68e0fee25c

STIX ID: report--17a34df4-d8a7-5363-8db1-df68e0fee25c

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2024-05-15

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence documents an active Storm-1811 campaign (mid‑April to May 2024) that uses Teams-based impersonation and vishing to trick users into granting access via Quick Assist, then delivers Qakbot, RMM tools, Cobalt Strike, and SystemBC to exfiltrate credentials and deploy Black Basta ransomware; the report provides IOCs, detection queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.