Your antivirus stayed silent for the entire attack

A while back, I got a message that looked like it came from my daughter. Urgent. She needed money.

For two seconds, it worked. Then I called her on the number I already had. She was fine. The message was not from her. I knew exactly what to do, and I still felt the pull.

Last month, one of my clients called me on a Tuesday morning. One of his staff had taken a Microsoft Teams call from someone claiming to be IT support. She followed their instructions, opened Quick Assist, and watched someone take control of her screen.

She ended the session after sixty seconds. Something felt off.

Same instinct I had. Not fast enough.

What happened in those sixty seconds

Stage 1. A Teams call from an external number claiming to be IT support. An urgent issue on her machine. Teams looked internal. She had no reason to question it.

Stage 2. She was walked through opening Quick Assist, a legitimate Microsoft remote-access tool that is pre-installed on Windows 11 and most Windows 10 machines. No download required. She had never heard of it. She shared the code.

Stage 3. With full screen control, the attacker ran a script in memory. Nothing written to disk. No antivirus alert. To this day we do not know what it did, because it left nothing to examine.

Stage 4. A second remote-access tool was installed from an unknown publisher. A backup pathway, independent of Quick Assist. The attacker now had two ways back in.

Stage 5. She ended the session. Something felt wrong. She was right. The PC was rebuilt. A cyber-insurance claim was filed.

Sixty seconds from first contact to two remote-access tools installed, with zero alerts from antivirus or EDR along the way.

Five things that would have stopped this

Disable Quick Assist. It can be turned off fleet-wide through Intune or Group Policy in minutes. If your team does not use it, remove it.

Remove local admin rights. A user without admin access cannot install software. Stage 4 never happens.

Train one rule, not a policy. Real IT never cold-calls asking for remote access. Hang up. Call your IT number directly. That is the whole training.

Require a callback before any remote session. Hang up. Call the number already on file. Thirty seconds. That is the gap this attack cannot close.

Enable script-block logging. If something runs in memory, you need a record. We had none. We still do not know what that script did.

The attackers are not after the user. They are after the network behind them.

If you want to know whether your team could walk through this attack without realising it, StillWater’s free cybersecurity risk scorecard takes five minutes: https://page.thriwin.io/stillwater/cybersecurity-risk-score/

Sources

Quick Assist availability and behaviour: Microsoft, Quick Assist documentation (Microsoft Learn).

Incident details: StillWater IT client engagement, May 2026.

Related reading