Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Microsoft Teams isn’t safe: Hackers are sneaking in through calls

Following the acquisition of access through AnyDesk, the attacker undertook further malicious actions and employed techniques to evade detection

byKerem Gülen
December 17, 2024
in News, Cybersecurity
Home News
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Cybercriminals are increasingly utilizing Microsoft Teams to execute vishing attacks aimed at accessing users’ systems. Trend Micro reported a specific incident that involved a series of phishing emails followed by a deceptive Microsoft Teams call. The fraudsters pretended to offer tech support and manipulated a victim into downloading remote access software.

Cybercriminals exploit Microsoft Teams for vishing attacks

The attack commenced with a barrage of phishing emails that targeted the victim’s inbox. Shortly after this initial contact, the attacker initiated a call through Microsoft Teams, masquerading as an employee of a company the victim trusted. During this call, the cybercriminal urged the victim to install a remote support application. The initial suggestion was Microsoft Remote Support, but when the installation encountered problems, the attacker pivoted to AnyDesk, a remote desktop tool commonly exploited by malicious actors.


AnyDesk hacked, reset your passwords immediately

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.


Once AnyDesk was installed on the victim’s machine, the attacker gained control over it. They proceeded to deploy various suspicious files, including one identified as Trojan.AutoIt.DARKGATE.D. This malware, delivered via an AutoIt script, enabled the attacker to execute malicious commands and maintain remote control over the system. The attacker executed several commands that gathered detailed information about the victim’s system, employing commands such as systeminfo, route print, and ipconfig /all, which saved the gathered data in a file named 123.txt.

Microsoft Teams isn’t safe. - Hackers are sneaking in through calls
Sequence of events outlining the timeline of the attack (Image: Trend Micro)

Following the acquisition of access through AnyDesk, the attacker undertook further malicious actions and employed techniques to evade detection. For example, AutoIt scripts were utilized to identify and bypass any antivirus software present on the system. Additionally, malicious files were discreetly downloaded and extracted into hidden directories, thereby reducing the likelihood of detection. Among these was a file named SystemCert.exe, which created additional scripts and executables in temporary folders and facilitated further malicious activities.

Fortunately, the attack was thwarted before any sensitive data was exfiltrated. The investigation revealed that, despite the hackers gaining access and leaving behind persistent files and registry entries, no critical information was stolen from the victim. This incident underscores the urgent need for fortified security measures within organizations to defend against such sophisticated threats.

Microsoft Teams isn’t safe. - Hackers are sneaking in through calls
Vision One’s analysis identifying the root cause behind script.a3x and Autoit3.exe creation (Image: Trend Micro)

Best practices to combat vishing attacks

Organizations must adopt comprehensive strategies to mitigate the risks associated with vishing attacks. It is crucial to first verify the claims made by third-party technical support providers. Employees should confirm affiliations before granting any access, which reduces the risk of manipulation by cybercriminals.

Controlling access to remote support tools is another key aspect of a robust security posture. Organizations should consider implementing whitelisting for approved tools like AnyDesk and enforce multi-factor authentication policies for enhanced security. This step adds a necessary layer of protection in preventing unauthorized access.

Employee training is paramount in building awareness around social engineering tactics, including phishing and vishing. Educating staff on recognizing these threats is vital in minimizing their susceptibility to future attacks. Training sessions should focus on the specific techniques used by cybercriminals, as well as practical steps to ensure safety.


Featured image credit: Dimitri Karastelev/Unsplash

Tags: Microsoft Teams

Related Posts

“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

June 12, 2026
How Henrique Schmaiske led Meteor.js through its biggest transformation

How Henrique Schmaiske led Meteor.js through its biggest transformation

June 12, 2026
Proven privacy: Why ‘no-log’ claims need real evidence today

Proven privacy: Why ‘no-log’ claims need real evidence today

June 12, 2026
ChatGPT hits 1 billion users as global AI adoption surges despite backlash

ChatGPT hits 1 billion users as global AI adoption surges despite backlash

June 12, 2026
Huawei launches HarmonyOS 7 developer beta with upgraded API 26

Huawei launches HarmonyOS 7 developer beta with upgraded API 26

June 12, 2026
OpenAI Codex referral program rewards users with extra rate resets

OpenAI Codex referral program rewards users with extra rate resets

June 12, 2026

LATEST NEWS

“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

How Henrique Schmaiske led Meteor.js through its biggest transformation

Proven privacy: Why ‘no-log’ claims need real evidence today

ChatGPT hits 1 billion users as global AI adoption surges despite backlash

Huawei launches HarmonyOS 7 developer beta with upgraded API 26

OpenAI Codex referral program rewards users with extra rate resets

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Roboto AI

Pickaxe

Pfpmaker

MindPal

Syllaby

ScreenApp

FinanceBrain

GitHub Spark

Hints

VisionStory AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.