When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

2026-05-13T19:23:44Z375e532a7b0c5e06151d3908f0480709a1d1228f04f6470e3be0813225bc700b
CVE-1999-0497CVE-2020-1472CVE-2023-36036CVE-2026-41089Dropbox-hosted payloadMetasploitMicrosoft TeamsModeloRATNetlogonPatch Tuesdaycommand-and-controlcredential harvestingdomain compromiseexfiltrationfake lock screenlateral movementliving-off-the-landprivilege escalationsocial engineering

What happened

Rapid7 analyzed a multi-stage enterprise intrusion that began with a Microsoft Teams message impersonating IT support to deliver a Dropbox-hosted Python payload (ModeloRAT). The payload established C2, deployed backdoors, mapped the network, and the actor escalated to SYSTEM using CVE-2023-36036 before presenting a fake Windows lock screen to harvest a domain password and pivot to domain compromise. The same Rapid7 feed also highlights May 2026 Patch Tuesday including a critical Windows Netlogon RCE (CVE-2026-41089, CVSS 9.8) that defenders should prioritize, and Metasploit updates referencing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
375e532a7b0c5e06151d3908f0480709a1d1228f04f6470e3be0813225bc700b
Enrichment time
2026-05-13T19:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.