Attackers Use Teams to Install A0Backdoor via Quick Assist

Attackers impersonated IT over Microsoft Teams and used Quick Assist to install A0Backdoor via signed MSI and DLL sideloading. A0Backdoor fingerprints hosts and hides C2 in DNS; block/monitor Quick Assist, require secondary verification, and hunt for signed MSI and hostfxr.dll indicators.

Part of the PlainSec briefing for 2026-03-15

Sources