When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Source: Rapid7 Blog  ·  Category: Threat Actor & Campaign


ModeloRAT campaign exploits Microsoft Teams with fake IT Support messages to achieve domain compromise. Law firms rely heavily on Teams for collaboration; this attack pattern is directly applicable. Immediate action: user awareness training, conditional access policies, and monitoring for Teams-based anomalies.

→ Read the full article

Read more