When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise
2026-05-13T19:23:44Z•375e532a7b0c5e06151d3908f0480709a1d1228f04f6470e3be0813225bc700b
CVE-1999-0497CVE-2020-1472CVE-2023-36036CVE-2026-41089Dropbox-hosted payloadMetasploitMicrosoft TeamsModeloRATNetlogonPatch Tuesdaycommand-and-controlcredential harvestingdomain compromiseexfiltrationfake lock screenlateral movementliving-off-the-landprivilege escalationsocial engineering
What happened
Rapid7 analyzed a multi-stage enterprise intrusion that began with a Microsoft Teams message impersonating IT support to deliver a Dropbox-hosted Python payload (ModeloRAT). The payload established C2, deployed backdoors, mapped the network, and the actor escalated to SYSTEM using CVE-2023-36036 before presenting a fake Windows lock screen to harvest a domain password and pivot to domain compromise. The same Rapid7 feed also highlights May 2026 Patch Tuesday including a critical Windows Netlogon RCE (CVE-2026-41089, CVSS 9.8) that defenders should prioritize, and Metasploit updates referencing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 375e532a7b0c5e06151d3908f0480709a1d1228f04f6470e3be0813225bc700b
- Enrichment time
- 2026-05-13T19:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.