Hacking

VEILDrive Attack Campaign Abuses Microsoft SaaS to Deliver Malware

Published  ·  3 min read

A sophisticated new threat campaign dubbed VEILDrive is leveraging legitimate Microsoft SaaS services — including Teams, SharePoint, Quick Assist, and OneDrive — to conduct targeted cyberattacks against critical infrastructure. This campaign, recently reported by Israeli cybersecurity firm Hunters, marks a shift in attacker strategy, utilizing trusted Microsoft platforms to distribute malware and bypass traditional security defenses.

Targeted Attack on Critical Infrastructure

VEILDrive was uncovered in September 2024 after Hunters responded to an incident involving “Org C,” a U.S.-based critical infrastructure organization. Attackers initially infiltrated the organization using a compromised Microsoft Teams account from a previous victim, "Org A," instead of creating a new account, allowing them to exploit the default “External Access” feature in Teams for seamless communication.

Multi-Stage Infection Chain

The attackers used Microsoft Teams to send spear-phishing messages to Org C’s employees, posing as IT personnel and requesting remote access via Quick Assist. Once access was granted, the threat actors directed users to download a ZIP file hosted on SharePoint, which contained a remote access tool (RAT) called LiteManager. This tool enabled attackers to establish scheduled tasks, ensuring the persistence of LiteManager’s remote monitoring software on the victim’s system.

In addition, a second ZIP file was delivered, embedding Java-based malware alongside the Java Development Kit (JDK). This malware employed hard-coded Entra ID (formerly Azure Active Directory) credentials to connect with an adversary-controlled OneDrive account, using Microsoft Graph API to receive and execute PowerShell commands. The Java malware also featured a fallback mechanism with an HTTPS socket linked to an Azure virtual machine, providing an alternative C2 channel.

Sophisticated Tactics and SaaS Exploitation

By leveraging Microsoft’s own platforms, VEILDrive exemplifies a “cloud-centric” approach to malware distribution, capitalizing on trusted infrastructures to evade detection. Hunters noted that the campaign’s lack of obfuscation and reliance on clear, readable code makes it stand out from typical evasion-focused malware, as it avoids sophisticated cloaking techniques in favor of structural simplicity.

This SaaS-dependent strategy poses significant detection challenges, as conventional monitoring systems are not optimized to flag malware concealed within legitimate software channels.

Additional Cases of Quick Assist Abuse

The Quick Assist tool used in this campaign has seen similar abuse in the past. In May 2024, Microsoft warned that the financially motivated group Storm-1811 had misused Quick Assist to drop Black Basta ransomware, masquerading as IT support to gain remote access.

Rising Threats via Legitimate Hosting Services

The VEILDrive campaign highlights an alarming trend of cybercriminals exploiting trusted file-sharing services like SharePoint, OneDrive, and Dropbox. Microsoft recently cautioned that attacks abusing these platforms are increasingly common, as they enable attackers to bypass security defenses by masking malicious activity as benign file transfers.

Defensive Measures and Recommendations

  1. Limit External Communication: Organizations should review and restrict external access settings in platforms like Microsoft Teams, reducing exposure to outside threats.
  2. Vigilance with SaaS Interactions: Employees should be trained to verify IT support requests and avoid granting remote access without proper verification.
  3. Enhanced Monitoring: Utilize advanced threat detection tools that recognize abnormal patterns in SaaS activity.

VEILDrive exemplifies the sophisticated tactics attackers are using to exploit trusted infrastructures for stealthy and targeted malware distribution. By understanding these tactics and proactively securing SaaS environments, organizations can reduce the risk of falling victim to similar campaigns.

 

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067