Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.004 SSH |
GroupStorm-1811 | Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access. |
| T1036.010 Masquerade Account Name |
GroupStorm-1811 | Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing. |
| T1059.003 Windows Command Shell |
GroupStorm-1811 | Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines. |
| T1087.002 Domain Account |
GroupStorm-1811 | Storm-1811 has performed domain account enumeration during intrusions. |
| T1105 Ingress Tool Transfer |
GroupStorm-1811 | Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices. |
| T1125 Video Capture |
ToolQuick Assist | Quick Assist allows for the remote administrator to view the interactive session of the running machine, including full screen activity. |
| T1204.002 Malicious File |
GroupStorm-1811 | Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity. |
| T1219.002 Remote Desktop Software |
GroupStorm-1811 | Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk. |
| T1482 Domain Trust Discovery |
GroupStorm-1811 | Storm-1811 has enumerated domain accounts and access during intrusions. |
| T1486 Data Encrypted for Impact |
GroupStorm-1811 | Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments. |
| T1566.002 Spearphishing Link |
GroupStorm-1811 | Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials. |
| T1566.003 Spearphishing via Service |
GroupStorm-1811 | Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel. |
| T1566.004 Spearphishing Voice |
GroupStorm-1811 | Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access. |
| T1585.003 Cloud Accounts |
GroupStorm-1811 | Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes. |
| T1588.002 Tool |
GroupStorm-1811 | Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations. |
| T1684.001 Impersonation |
GroupStorm-1811 | Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.