Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Date: 09/03/2026

    Severity: High

    Summary

    Threat Intelligence observed a human-operated intrusion campaign in which attackers impersonate IT support personnel through Microsoft Teams and use social engineering and remote support tools to gain interactive access. The attackers deploy a malicious MSI loader, stage a Node.js-based JavaScript backdoor, establish C2 over HTTPS, conduct host and Active Directory reconnaissance, capture screenshots, and execute additional payloads through PowerShell and rundll32. The campaign ultimately uses WinRM (TCP 5985) for credential-backed lateral movement toward high-value assets such as domain controllers and certificate authorities, indicating a potential path to data theft, extortion, or ransomware deployment. 

    Indicators of Compromise (IOC) List    

    DOmain/URLs

    update1n5.blob.core.windows.net

    update1n6.blob.core.windows.net

    update1n7.blob.core.windows.net

    update1n9.blob.core.windows.net

    updatetmp.blob.core.windows.net

    synctimes.australiaeast.cloudapp.azure.com

    webwether.eastus.cloudapp.azure.com

    dssdfvsdfvsdfvsdgbfbdvdzv.org

    Hash

    4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d

    a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676

    cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5

    0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3

    69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23

    a135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "dssdfvsdfvsdfvsdgbfbdvdzv.org" or url like "dssdfvsdfvsdfvsdgbfbdvdzv.org" or siteurl like "dssdfvsdfvsdfvsdgbfbdvdzv.org" or domainname like "update1n7.blob.core.windows.net" or url like "update1n7.blob.core.windows.net" or siteurl like "update1n7.blob.core.windows.net" or domainname like "update1n5.blob.core.windows.net" or url like "update1n5.blob.core.windows.net" or siteurl like "update1n5.blob.core.windows.net" or domainname like "update1n6.blob.core.windows.net" or url like "update1n6.blob.core.windows.net" or siteurl like "update1n6.blob.core.windows.net" or domainname like "update1n9.blob.core.windows.net" or url like "update1n9.blob.core.windows.net" or siteurl like "update1n9.blob.core.windows.net" or domainname like "webwether.eastus.cloudapp.azure.com" or url like "webwether.eastus.cloudapp.azure.com" or siteurl like "webwether.eastus.cloudapp.azure.com" or domainname like "updatetmp.blob.core.windows.net" or url like "updatetmp.blob.core.windows.net" or siteurl like "updatetmp.blob.core.windows.net" or domainname like "synctimes.australiaeast.cloudapp.azure.com" or url like "synctimes.australiaeast.cloudapp.azure.com" or siteurl like "synctimes.australiaeast.cloudapp.azure.com"

    Detection Query 2 :

    sha256hash IN ("4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d","cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5","a135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87","69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23","a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676","0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3")

    Reference: 

    https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/            


    Tags

    MalwareThreat ActorMicrosoftSocial EngineeringLoaderBackdoorActive DirectoryScreen capturePowerShell AttackRansomwareExtortionData StealerCredential Harvesting

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags