Threat actors are using voice phishing (vishing) attacks via Microsoft Teams in an attempt to trick victims into installing the DarkGate malware, according to researchers at Trend Micro.
“The attacker used social engineering to manipulate the victim to gain access and control over a computer system,” Trend Micro says.
“The victim reported that she first received several thousands of emails, after which she received a call via Microsoft Teams from a caller claiming to be an employee of an external supplier. During the call, the victim was instructed to download Microsoft Remote Support application, however, the installation via the Microsoft Store failed.
The attacker then instructed the victim to download AnyDesk via browser and manipulate the user to enter her credentials to AnyDesk.”
Fortunately, this particular attack was thwarted before the attacker caused any damage. However, Trend Micro notes that similar attacks have led to ransomware deployment.
“DarkGate is primarily distributed through phishing emails, malvertising, and SEO poisoning. However, in this case, the attacker leveraged voice phishing (vishing) to lure the victim,” the researchers write. “The vishing technique has also been documented by Microsoft, in a case where the attacker utilized QuickAssist to gain access to its target to distribute ransomware.”
The researchers add that security awareness training can help employees thwart social engineering attacks, preventing attackers from gaining access in the first place.
“Provide employee training to raise awareness about social engineering tactics, phishing attempts, and the dangers of unsolicited support calls or pop-ups,” Trend Micro says. “Well-informed employees are less likely to fall victim to social engineering attacks, strengthening the organization’s overall security posture.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Trend Micro has the story.