Warning about new ransomware tactics: How to protect yourself!

29. November 2024

Recently, organizations have been confronted with a new ransomware method that is particularly sophisticated. It’s important to be aware of this tactic to protect yourself and your organization. Here are the details and specific recommendations for action:

The new scam

Attackers use a multi-stage method:

  1. Initial contact: Contact details of the target persons are collected by telephone.
  2. Spam attack: Users are flooded with thousands of spam messages via e-mail or Teams.
  3. Fake IT calls: The attackers call and pretend to be IT support to offer help with spam removal.
  4. Quick Assist as a backdoor: They use Microsoft Quick Assist to gain remote access to the system via a 6-digit PIN. While apparently solving the spam problem, they install an SSH backdoor.
  5. Further steps: The system is handed over to another team, which spreads laterally across the network, exfiltrates data and finally encrypts the systems.

Two important findings:

  1. Report spam attacks to IT immediately and do not accept blind offers of help. Verify every call, even if it appears to come from IT.
  2. Check and deactivate Microsoft Quick Assist.
    • Quick Assist is installed as standard in Windows 10 and 11 (including Professional and Enterprise) and can bypass firewalls and VPNs.
    • To check whether Quick Assist is active: Press the Windows key, enter “Quick” and search for “Quick Assist”.
    • Remove Quick Assist centrally: It is a security risk that attackers can easily exploit.

You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information

Similar posts

Today I would like to share my experience with OSCP from the guys at Offensive Security. Why OSCP? There are [...]

11. August 2017

I decided to set up a new team of infosec professionals, because of a lot of project requests and my [...]

25. October 2018

It’s funny that two independent companies name the “21” cybersecurity and redteaming resources in the world. But I appreciate being [...]

8. July 2019

I had a lot of fun with an anniversary edition of the podcast “Ones & Zeros, IT Simply Explained” at [...]

25. August 2020