Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion
Dec. 13, 2024, 3:59 p.m.
Tags
External References
Description
An attacker used social engineering via a Microsoft Teams call to impersonate a client and gain remote access to a user's system. The victim was tricked into downloading AnyDesk, allowing the attacker to drop suspicious files, including DarkGate malware. The attack involved multiple stages, including the execution of malicious commands, system information gathering, and connection to a command-and-control server. The DarkGate payload was delivered through an AutoIt script, which injected itself into legitimate processes. Although persistent files and a registry entry were created, the attack was thwarted before data exfiltration occurred. The incident highlights the importance of robust security measures and awareness against social engineering attacks.
Date
Published: Dec. 13, 2024, 12:40 p.m.
Created: Dec. 13, 2024, 12:40 p.m.
Modified: Dec. 13, 2024, 3:59 p.m.
Attack Patterns
DarkGate
T1059.005
T1059.003
T1059.001
T1547.001
T1614
T1016
T1070
T1082
T1105
T1055
T1036
T1204
T1140
T1027
T1566
T1059