Cybercriminals Exploiting Microsoft’s Quick Assist Feature in Ransomware Attacks
ID: 58b6765c-e5e0-5a9f-905a-5817ea6795a7
STIX ID: report--58b6765c-e5e0-5a9f-905a-5817ea6795a7
Feed Name: The Hacker News
Threat Score
Microsoft and industry reporting show the financially motivated group "Storm-1811" is conducting a campaign (since ~April 2024) that uses voice phishing and abuse of the Quick Assist remote-support tool to gain interactive access, chain-install QakBot and Cobalt Strike, and deploy Black Basta ransomware across multiple industries; organizations are advised to block or uninstall unused RMM tools and train staff to recognize tech-support scams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
