logo

Threat Spotlight: Hijacked and Hidden: New Backdoor and Persistence Technique

ID: bbea74f3-f1bc-5b92-b3b4-877a045dea8e

STIX ID: report--bbea74f3-f1bc-5b92-b3b4-877a045dea8e

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2025-04-11

Date Updated: 2026-04-29

...
...

**ReliaQuest discovered a targeted Microsoft Teams phishing campaign (targeting finance and professional services) that used social-engineering to gain Quick Assist remote access, installed a new PowerShell backdoor delivered via a Google Drive-hosted text file, and achieved persistence through a novel TypeLib COM hijacking technique; the report provides code snippets, C2/Telegram indicators, development/testing evidence from VirusTotal, and mitigation guidance.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.