Threat Advisory

Vishing Attack Deploys DarkGate Malware Through AnyDesk & Microsoft Teams

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A recent security incident highlights the growing threat of social engineering attacks targeting corporate environments. An attacker used a Microsoft Teams call to impersonate a trusted client, exploiting this interaction to manipulate the victim into downloading Any Desk , a remote desktop tool. The attacker then leveraged this access to deploy the DarkGate malware, which enabled remote control, executed malicious commands, gathered sensitive system data, and connected to a C2 server.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A recent security incident highlights the growing threat of social engineering attacks targeting corporate environments. An attacker used a Microsoft Teams call to impersonate a trusted client, exploiting this interaction to manipulate the victim into downloading Any Desk , a remote desktop tool. The attacker then leveraged this access to deploy the DarkGate malware, which enabled remote control, executed malicious commands, gathered sensitive system data, and connected to a C2 server.[emaillocker id="1283"]

The attack commenced with social engineering, where the victim was inundated with emails before receiving a call from an individual posing as an IT representative of a trusted vendor. The attacker instructed the victim to download Any Desk, bypassing an unsuccessful attempt with a Microsoft Remote Support application. Once Any Desk was installed, the attacker deployed DarkGate malware, delivered via an Autoit script (script.a3x) executed by AutoIt3.exe. This script enabled system discovery, defense evasion, and communication with a C&C server. The malware exploited DLL side-loading techniques and utilized legitimate processes like MicrosoftEdgeUpdateCore.exe to evade detection. Subsequent activities included creating persistent files, modifying registry entries, and executing malicious payloads such as SystemCert.exe and StaticSrv.exe, all of which facilitated the attack's progression.

The DarkGate intrusion was thwarted before exfiltration occurred, highlighting the importance of robust security measures. This attack underscores the evolving landscape of cyber threats, where attackers employ creative tactics like vishing and leveraging legitimate tools for malicious purposes. Organizations must adopt a layered security strategy, combining advanced detection tools, employee training, and strict controls over third-party applications. By enhancing awareness and implementing proactive defenses, businesses can mitigate the risk of similar attacks and safeguard their digital environments.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1204 User Execution
Persistence T1547 Boot or Logon AutoStart Execution
Defense Evasion T1078 Valid Accounts
T1218 Signed Binary Proxy Execution
T1140 Deobfuscate/Decode Files or Information
T1562 Impair Defenses
Discovery T1082 System Information Discovery
T1016 System Network Configuration Discovery
Command and Control (C2) T1071 Application Layer Protocol
Exfiltration T1020 Automated Exfiltration

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/12/attackers-exploit-microsoft-teams-and.html

[/emaillocker]
crossmenu