Skip to main content
DarkGate via Microsoft Teams: External Message Lure operation cover
COMING SOONIntermediate

DarkGate via Microsoft Teams: External Message Lure

An IT helpdesk coordinator at a logistics firm receives an urgent Teams chat from an external IT support account. The message links to a VBS script disguised as a VPN update. Running it kicks off a silent MSI install that drops a renamed AutoIt3 loader, which decrypts DarkGate in memory, registers a scheduled task for persistence, and begins beaconing to an HTTPS C2 server. Trace the chain from the Teams lure through the loader to the active backdoor.

50m
7 tasks
50 points
Free

Launches in 5 days

Jul 28, 2026

Tuesday, July 28, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

XDRSIEMEmail

What you'll investigate

7 objectives unlock when this operation goes live.

1Trace the first contact
2Name the lure file
3Find the staging server
4Expose the loader binary
5Locate the persistence mechanism
6Cut the C2 channel
7Classify the installer evasion technique

Be first when it launches

Create your free account now. The moment this operation goes live on Jul 28, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free