216.73.217.22

Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion

· Published 13/12/2024 12:40 · Modified 13/12/2024 15:59

Export JSON

Essential information

Published
13/12/2024 12:40
Modified
13/12/2024 15:59
Tags
2024-12-13 darkgate vishing
Related entities
16 techniques (mitre), 1 malware

Description

An attacker used social engineering via a Microsoft Teams call to impersonate a client and gain remote access to a user's system. The victim was tricked into downloading AnyDesk, allowing the attacker to drop suspicious files, including malware. The attack involved multiple stages, including the execution of malicious commands, system information gathering, and connection to a command-and-control server. The payload was delivered through an AutoIt script, which injected itself into legitimate processes. Although persistent files and a registry entry were created, the attack was thwarted before data exfiltration occurred. The incident highlights the importance of robust security measures and awareness against social engineering attacks.

External references