A new, highly sophisticated vishing campaign has emerged, revealing a worrying shift by cybercriminals towards exploiting legitimate corporate tools to distribute malware. The method they are using combines deceptive calls, social engineering and collaboration tools , creating a unique hybrid of voice phishing that skillfully evades traditional security systems.

The New Approach: Voice Phishing with Corporate Tools
The attackers use Microsoft Teams and appear under fake names that mimic internal IT administrators. In this way, they create an environment of false credibility and a sense of urgency, prompting the victim to immediately carry out instructions without a second thought.
See also: JS#SMUGGLER: Compromised websites for NetSupport RAT deployment
Their goal is to trick the user into launching Microsoft QuickAssist, the built-in Windows remote support tool. Using a native tool helps them bypass defenses that typically flag third-party applications as suspicious. Once access is established, the malware begins to deploy in multiple stages.
How the vishing attack works step by step
SpiderLabs , which analyzed the campaign, revealed that after taking remote control, the attackers redirect the victim to a malicious website, ciscocyber[.]com . What is striking is that the redirection does not happen immediately: the criminals delay for about ten minutes before initiating the final stage of the infection.
This delay is not accidental; it is a carefully designed tactic to reduce suspicion and avoid triggering automated detection mechanisms. Ultimately, the victim is led to execute a seemingly legitimate update, which in fact contains the main malicious payload.
See also: Hackers exploit ad networks to distribute Triada Trojan

An attack based on social engineering
Unlike many modern cyberattacks, this campaign does not exploit a software vulnerability. Its success relies almost exclusively on persuasion, pressure, and the abuse of human trust.
The attackers are leveraging .NET wrapper- based malware , allowing code to be executed directly in memory. This drastically reduces the digital footprint that malware typically leaves behind and makes post-attack analysis more difficult.
Technical Analysis: The chain of infection under the lens
At the heart of the attack is updater.exe, an executable file built on .NET Core 8.0. This file is nothing more than a wrapper for loader.dll, which handles the critical stage of communication with the command and control server, jysync[.]info.
Once the connection is established, the loader retrieves encryption keys necessary to decrypt the final payload. The process uses a combination of AES-CBC and XOR, allowing the malware to unlock the content — without ever writing it to disk.
See also: OceanLotus Group targets Xinchuang IT ecosystems
The payload is loaded directly into memory via .NET reflection, a technique that makes the malware extremely difficult to detect, especially by security solutions that rely on file scans.

Why this campaign raises the bar of threat
The use of trusted tools, social engineering, and “fileless” execution techniques make this campaign particularly dangerous. Vishing attacks are evolving rapidly and are no longer limited to simple phone calls, but instead incorporate complex infrastructure and technologies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The experts' recommendation is clear: strengthen user awareness, restrict access to remote assistance tools, and strictly verify identity for any unexpected call from "IT support."
