When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise
Source: Rapid7 Blog · Category: Threat Actor & Campaign
ModeloRAT campaign exploits Microsoft Teams with fake IT Support messages to achieve domain compromise. Law firms rely heavily on Teams for collaboration; this attack pattern is directly applicable. Immediate action: user awareness training, conditional access policies, and monitoring for Teams-based anomalies.