Threat Spotlight: Hijacked and Hidden: New Backdoor and Persistence Technique
ID: bbea74f3-f1bc-5b92-b3b4-877a045dea8e
STIX ID: report--bbea74f3-f1bc-5b92-b3b4-877a045dea8e
Feed Name: ReliaQuest Blog
Threat Score
**ReliaQuest discovered a targeted Microsoft Teams phishing campaign (targeting finance and professional services) that used social-engineering to gain Quick Assist remote access, installed a new PowerShell backdoor delivered via a Google Drive-hosted text file, and achieved persistence through a novel TypeLib COM hijacking technique; the report provides code snippets, C2/Telegram indicators, development/testing evidence from VirusTotal, and mitigation guidance.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
