Attackers impersonated IT over Microsoft Teams and used Quick Assist to install A0Backdoor via signed MSI and DLL sideloading. A0Backdoor fingerprints hosts and hides C2 in DNS; block/monitor Quick Assist, require secondary verification, and hunt for signed MSI and hostfxr.dll indicators.
Part of the PlainSec briefing for 2026-03-15