lmika
lmika

🔗 The Axios supply chain attack used individually targeted social engineering

they scheduled a meeting with me to connect. the meeting was on ms teams. […] the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT.

Ah, an interesting way to get someone to install something: throwing up an install prompt minutes before needing to join a meeting. Exploiting probably the most annoying aspect of video conferencing software.

|
Embed
Progress spinner