logo

48 Minutes: How Fast Phishing Attacks Exploit Weaknesses

ID: 1c0424ed-a3ac-5649-bf0f-989bbf420d85

STIX ID: report--1c0424ed-a3ac-5649-bf0f-989bbf420d85

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2025-02-20

Date Updated: 2026-04-29

...
...

ReliaQuest investigated a manufacturing-sector breach where attackers used mass spam and Microsoft Teams help-desk impersonation to convince users to grant remote control via Quick Assist, then performed DLL sideloading (winhttp.dll in OneDriveStandaloneUpdater), established HTTPS C2 to uptemp.icu, attempted lateral movement via SMB and RDP with PowerShell-created scheduled tasks, escalated privileges by abusing a SQL service account to create domain admin accounts, and exfiltrated sensitive data to pefidesk.com; the report includes IOCs, MITRE ATT&CK mappings, detection rules, and automated response playbooks and warns that attacker breakout times (48 minutes in this case) demand faster, automated containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.