Product
Quick Assist
- First Reported
- Jul 22, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (3)
- takeover. An attacker impersonated IT support through an external Microsoft Teams tenant and used Quick Assist to obtain remote access and steal credentials. After the malicious Quick Assist session ended, the ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- vishing and then steering victims toward legitimate remote support and remote access tooling (such as Quick Assist and in some cases other common remote support utilities). From there, attackers deploy tooling that ThreatLabz Report: Ransomware Data Theft Surges as Attackers Target High-Impact Employees
- victim. The threat actors then initiated a screen-sharing session and instructed the victim to launch Quick Assist. After obtaining hands-on access, they navigated to an Amazon S3-hosted phishing site and downloaded UNC6692 Uses Email Bombing, IT Impersonation and Quick Assist to Deploy Edgecution
CVE (1)
Malware (4)
Threat Actors (7)
MITRE ATT&CK (28)
Vendors (7)
Products (18)
Tools (4)
Industries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.