
Helpdesk Hijackers Turn Quick Assist Sessions Into Persistent Backdoor and Proxy Access
Active since January 202620262026, the activity appears linked to an initial access broker that may sell or provide compromised environments to ransomware operators. The attackers impersonate IT or helpdesk personnel and contact victims through Microsoft Teams. In many cases, the social-engineering attempt is believed to follow spam bombing, where a target receives a large volume […]
The post Helpdesk Hijackers Turn Quick Assist Sessions Into Persistent Backdoor and Proxy Access appeared first on Cyber Security News.