Attack Times Are Shortening, Requiring Response Times To Match

According to reports, dozens of companies across the U.S. and Canada have been targeted by malware that utilizes Microsoft Teams.

Threat group STAC4749 has been initiating chats or calls via Microsoft Teams. Their communications attempt to trick victims by offering help desk or IT support.

A remote session is initiated through Microsoft Quick Assist or cloud-based RemSupp. The attackers then deploy PowerShell, which establishes persistence and executes malware.

In at least three cases involving this scheme, the attackers deployed Chaos ransomware into the compromised system.

In one case, the time from initial compromised access to ransomware deployment was 17 hours.

Targeted organizations were mainly in the industries of services, manufacturing, energy, construction, and engineering.

Source: https://www.cybersecuritydive.com/news/hackers-microsoft-teams-ransomware-it-support/826591/

Commentary

The above matter states that criminals are operating within a very short attack window, with only 17 hours passing between the initial contact to the malware deployment in one matter. Shorter windows give targets a much smaller window for their remediation efforts, especially those with slow response protocols.

Organizations must pre-plan their defense and detection strategies. In particular, they must tighten their standards to include lists of pre-approved and disallowed remote access tools. Any non-approved remote access tools should be prohibited. In addition, they must train on the risks associated with help desk and IT support scams.

The final takeaway is faster attacks require faster organizational responses. Work with your IT department to keep current on strategies for attack prevention.

Finally, your opinion is important to us. Please complete the opinion survey: