---
title: Microsoft Teams and QuickAssist Exploited in New Vishing Attack to Spread .NET Malware
metaTitle: "MS Teams Vishing Attack Spreads .NET Malware"
description: "Posing as senior IT staff via MS Teams calls, threat actors persuade employees to grant them remote access, ultimately delivering data-stealing malware."
slug: ms-teams-vishing-spreads-dot-net-malware
date: "2025-12-09T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/ms-teams-vishing-malware-attack.webp"
  alt: A cartoon of a robot in a sharp business suit.
sourcePublisher:
  name: Cyber Press
  url: "https://cyberpress.org/"
sourceArticle:
  url: "https://cyberpress.org/net-malware/"
tags: [Vishing, Tech Support Scam, Malware]
status: published
---

A new multi-stage vishing campaign has been uncovered that uses Microsoft Teams calls and the QuickAssist tool to deliver fileless .NET malware.

The attack begins when the victim receives a Teams call from a threat actor impersonating a senior IT staff member via a spoofed display name.

Using social engineering, the attacker persuades the user to launch QuickAssist, thereby granting remote access to the device under the guise of a legitimate support request.

Within approximately ten minutes of the session, the victim is redirected to a fake verification page hosted at ciscocyber[.]com/verify.php, which delivers a malicious file named “updater.exe” disguised as a harmless software updater...
