Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
ID: 17a34df4-d8a7-5363-8db1-df68e0fee25c
STIX ID: report--17a34df4-d8a7-5363-8db1-df68e0fee25c
Feed Name: Microsoft Security
Threat Score
Microsoft Threat Intelligence documents an active Storm-1811 campaign (mid‑April to May 2024) that uses Teams-based impersonation and vishing to trick users into granting access via Quick Assist, then delivers Qakbot, RMM tools, Cobalt Strike, and SystemBC to exfiltrate credentials and deploy Black Basta ransomware; the report provides IOCs, detection queries, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
