HomeSecurityVishing attack abuses Teams & QuickAssist to deploy .NET malware

Vishing attack abuses Teams & QuickAssist to deploy .NET malware

A new, highly sophisticated vishing campaign has emerged, revealing a worrying shift by cybercriminals towards exploiting legitimate corporate tools to distribute malware. The method they are using combines deceptive calls, social engineering and collaboration tools , creating a unique hybrid of voice phishing that skillfully evades traditional security systems.

vishing Teams & QuickAssist

The New Approach: Voice Phishing with Corporate Tools

The attackers use Microsoft Teams and appear under fake names that mimic internal IT administrators. In this way, they create an environment of false credibility and a sense of urgency, prompting the victim to immediately carry out instructions without a second thought.

See also: JS#SMUGGLER: Compromised websites for NetSupport RAT deployment

Their goal is to trick the user into launching Microsoft QuickAssist, the built-in Windows remote support tool. Using a native tool helps them bypass defenses that typically flag third-party applications as suspicious. Once access is established, the malware begins to deploy in multiple stages.

How the vishing attack works step by step

SpiderLabs , which analyzed the campaign, revealed that after taking remote control, the attackers redirect the victim to a malicious website, ciscocyber[.]com . What is striking is that the redirection does not happen immediately: the criminals delay for about ten minutes before initiating the final stage of the infection.

This delay is not accidental; it is a carefully designed tactic to reduce suspicion and avoid triggering automated detection mechanisms. Ultimately, the victim is led to execute a seemingly legitimate update, which in fact contains the main malicious payload.

See also: Hackers exploit ad networks to distribute Triada Trojan

Vishing attack abuses Teams & QuickAssist to deploy .NET malware

An attack based on social engineering

Unlike many modern cyberattacks, this campaign does not exploit a software vulnerability. Its success relies almost exclusively on persuasion, pressure, and the abuse of human trust.

The attackers are leveraging .NET wrapper- based malware , allowing code to be executed directly in memory. This drastically reduces the digital footprint that malware typically leaves behind and makes post-attack analysis more difficult.

Technical Analysis: The chain of infection under the lens

At the heart of the attack is updater.exe, an executable file built on .NET Core 8.0. This file is nothing more than a wrapper for loader.dll, which handles the critical stage of communication with the command and control server, jysync[.]info.

Once the connection is established, the loader retrieves encryption keys necessary to decrypt the final payload. The process uses a combination of AES-CBC and XOR, allowing the malware to unlock the content — without ever writing it to disk.

See also: OceanLotus Group targets Xinchuang IT ecosystems

The payload is loaded directly into memory via .NET reflection, a technique that makes the malware extremely difficult to detect, especially by security solutions that rely on file scans.

Vishing attack abuses Teams & QuickAssist to deploy .NET malware

Why this campaign raises the bar of threat

The use of trusted tools, social engineering, and “fileless” execution techniques make this campaign particularly dangerous. Vishing attacks are evolving rapidly and are no longer limited to simple phone calls, but instead incorporate complex infrastructure and technologies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The experts' recommendation is clear: strengthen user awareness, restrict access to remote assistance tools, and strictly verify identity for any unexpected call from "IT support."

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS