Today > 13 Critical | 36 High | 32 Medium vulnerabilities   -   You can now download lists of IOCs here!

Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion

Dec. 13, 2024, 3:59 p.m.

Description

An attacker used social engineering via a Microsoft Teams call to impersonate a client and gain remote access to a user's system. The victim was tricked into downloading AnyDesk, allowing the attacker to drop suspicious files, including DarkGate malware. The attack involved multiple stages, including the execution of malicious commands, system information gathering, and connection to a command-and-control server. The DarkGate payload was delivered through an AutoIt script, which injected itself into legitimate processes. Although persistent files and a registry entry were created, the attack was thwarted before data exfiltration occurred. The incident highlights the importance of robust security measures and awareness against social engineering attacks.

Date

Published: Dec. 13, 2024, 12:40 p.m.

Created: Dec. 13, 2024, 12:40 p.m.

Modified: Dec. 13, 2024, 3:59 p.m.

Attack Patterns

DarkGate

T1059.005

T1059.003

T1059.001

T1547.001

T1614

T1016

T1070

T1082

T1105

T1055

T1036

T1204

T1140

T1027

T1566

T1059