VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware
As part of its strategy, a persistent malware campaign known as VEILDrive has been seen exploiting trustworthy Microsoft services like Teams, SharePoint, Quick Assist, and OneDrive.
According to a recent report by Israeli cybersecurity firm Hunters, the attacker used Microsoft SaaS services, such as Teams, SharePoint, Quick Assist, and OneDrive, to distribute spear-phishing attacks and store malware on the trusted infrastructures of previously compromised organizations.
The threat actor was able to evade detection by traditional monitoring systems by adopting this cloud-centric approach.
According to Hunters, it became aware of the campaign in September 2024 while responding to a cyberattack against a US critical infrastructure company read more about VEILDrive Attack Exploits Mi...

