logo

Cybercriminals Exploiting Microsoft’s Quick Assist Feature in Ransomware Attacks

ID: 58b6765c-e5e0-5a9f-905a-5817ea6795a7

STIX ID: report--58b6765c-e5e0-5a9f-905a-5817ea6795a7

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-16

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Microsoft and industry reporting show the financially motivated group "Storm-1811" is conducting a campaign (since ~April 2024) that uses voice phishing and abuse of the Quick Assist remote-support tool to gain interactive access, chain-install QakBot and Cobalt Strike, and deploy Black Basta ransomware across multiple industries; organizations are advised to block or uninstall unused RMM tools and train staff to recognize tech-support scams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.