Quick Assist

Malware

⚠️ Overview

Quick Assist is a legitimate built‑in Windows remote assistance tool that has been widely abused by threat actors as a living‑off‑the‑land (LotL) remote access trojan (RAT), first documented in abuse campaigns by AT&T Alien Labs and the Federal Bureau of Investigation (FBI) in 2020. The tool is part of the Microsoft Windows operating system and is not malicious by itself; however, adversaries—including those linked to the TA551 (UNC1878) threat group and BazaLoader campaigns—employ social engineering to trick victims into launching Quick Assist, thereby granting the attacker remote desktop control. According to the MITRE ATT&CK framework, this abuse is classified under technique T1219 (Remote Access Software).

🔧 Technical Capabilities

Quick Assist does not propagate autonomously; it relies on initial human interaction via phishing emails, tech‑support scam telephone calls, or fake pop‑up alerts that instruct the victim to enter a specific 6‑digit security code provided by the attacker. Once the victim launches Quick Assist and inputs the code, the attacker gains full, unrestricted remote access to the victim’s desktop environment. The session uses Microsoft’s own encrypted communication infrastructure (hosted at *.quickassist.microsoft.com), making network traffic appear legitimate and evading traditional signature‑based detection. Persistence is not inherent but can be achieved by the attacker installing a backdoor or scheduled task after gaining access. Evasion techniques include masquerading as a legitimate Microsoft support session, using the tool’s default process name (QuickAssist.exe), and leveraging HTTPS traffic to blend in with normal Microsoft services. The tool does not require any C2 infrastructure of its own, as it operates entirely through Microsoft’s cloud‑based relay servers.

📜 History & Notable Incidents

The first major documented abuse of Quick Assist occurred in 2020 when the TA551 group used it to deliver BazaLoader, as reported by Proofpoint and AT&T Alien Labs. In 2021, the FBI issued a public warning (FLASH alert AA21‑263A) detailing multiple incidents where Quick Assist was leveraged in tech‑support scams leading to ransomware deployments, including Ryuk and Conti. High‑profile victims include organizations in the healthcare and manufacturing sectors, with the largest known campaign affecting over 1,000 users in a single month during 2021 (source: FBI). No specific CVEs have been assigned to Quick Assist itself, as the tool is legitimate; the vulnerabilities exploited are social engineering and user trust.

🔍 Detection Indicators

Network‑based indicators include outbound TLS connections to domains under *.quickassist.microsoft.com and the specific IP ranges 13.107.6.0/24 and 13.107.18.0/23 used by Microsoft’s Remote Desktop service. Behavioral signatures include the rapid launch of QuickAssist.exe followed by spawning of cmd.exe, PowerShell, or mshta.exe within the Remote Assistance session. Registry modifications are uncommon; however, the presence of the string “Quick Assist” in process command lines (e.g., “C:WindowsSystem32QuickAssist.exe”) alongside a 6‑digit code entry is a strong indicator. No fixed mutex names or file hashes are publicly documented, as the binaries are digitally signed by Microsoft and vary per Windows build.

☠️ Risk & Impact

Quick Assist abuse enables complete remote control of a victim’s machine, allowing attackers to exfiltrate sensitive data, deploy additional malware (e.g., BazaLoader, Cobalt Strike), and ultimately execute ransomware—causing financial losses of millions in ransom payments and operational downtime. The primary affected sectors are healthcare, manufacturing, and small‑to‑medium businesses, as reported in FBI and CISA advisories. Damage is compounded by the difficulty of detection due to the tool’s legitimate nature; businesses have lost entire networks after a single Quick Assist session.

🛡️ Mitigation

Organizations should disable Quick Assist via Group Policy or AppLocker for all users who do not require remote support, as recommended by the NSA’s “Immediate Actions to Protect Against Current Cyber Threats” guidance (August 2023). Additionally, deploy endpoint detection and response (EDR) rules that alert on QuickAssist.exe execution combined with unusual child processes, and train users never to install or launch remote assistance tools in response to unsolicited phone calls or emails.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.