all InfoSec news
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
Malware Analysis, News and Indicators - Latest topics malware.news
Since mid-April 2024, Microsoft Threat Intelligence has observed the threat actor Storm-1811 misusing the client management tool Quick Assist to target users in social engineering attacks. Storm-1811 is a financially motivated cybercriminal group known to deploy Black Basta ransomware. The observed activity begins with impersonation through voice phishing (vishing), followed by delivery of malicious tools, including remote monitoring and management (RMM) tools like ScreenConnect and NetSupport Manager, malware like Qakbot, Cobalt Strike, and ultimately Black Basta ransomware.
MITIGATE …
actor april attacks basta black basta black basta ransomware client cybercriminal deploy engineering impersonation intelligence management microsoft microsoft threat intelligence phishing ransomware social social engineering social engineering attacks storm target threat threat actor threat actors threat intelligence tool voice voice phishing