HomeYoutubeMicrosoft Teams: Fake calls from IT support lead to distribution of EtherRAT

Microsoft Teams: Fake IT support calls lead to EtherRAT distribution

New malicious campaign distributes EtherRAT malware via Microsoft Teams and legitimate remote access.

Social engineering attacks are evolving and are no longer limited to traditional phishing emails. A new campaign discovered by cybersecurity researchers shows that attackers are increasingly leveraging the collaborative capabilities offered by modern communication platforms, with Microsoft Teams taking center stage this time. The new method is based on a combination of email phishing, voice calls via Teams, and legitimate remote access tools , with the ultimate goal of installing the EtherRAT malware . In this way, attackers gain access to corporate computers, creating the conditions for further breaching the entire corporate network.

How the attack begins

The attack follows a well-organized sequence of actions designed to reduce the user's suspicions. According to a report by Unit 42, the victim first receives an email that appears to be an internal communication and includes a supposed employee survey along with an attached PDF file.

See also: Prompt Injection: AI agents make crypto payments without authorization

A few minutes after the document is opened, a voice call is made via Microsoft Teams from an account posing as a technical support manager or systems administrator. The attacker exploits the sense of trust that a live conversation creates and attempts to convince the employee that immediate technical intervention is required.

Although Teams displays a warning that this is an external account, many users ignore this warning, especially when the person you're talking to uses professional jargon and presents themselves as a member of the IT department.

Microsoft Teams: Fake IT support calls lead to EtherRAT distribution

From remote access to EtherRAT installation

After gaining the victim's trust, the attacker requests the activation of screen sharing or remote control functionality. He then guides the user to install well-known remote management applications, such as HopToDesk and AnyDesk, which are widely used in legitimate corporate processes.

The use of these tools makes it difficult to detect the attack, as many security solutions do not consider them malicious in themselves. A special Node.js-based loader is then installed, which downloads and activates the EtherRAT without easily raising suspicion.

Microsoft Teams EtherRAT

What is EtherRAT?

EtherRAT is a modern Remote Access Trojan (RAT) designed to take complete remote control of infected systems. It is compatible with different operating systems and allows attackers to execute commands, manipulate files, collect sensitive data , and maintain a persistent presence on the computer.

Of particular interest is the fact that it uses technologies related to Ethereum smart contracts to retrieve information about the active command and control server. This approach makes it difficult to detect and disable the attackers' infrastructure, as communication does not rely solely on fixed servers.

See also: TrojPix: New method of data leakage from air-gapped systems

At the same time, researchers identified multiple versions of the same installer, indicating that this campaign is constantly evolving and adapting to bypass modern security systems.

Microsoft Teams under the microscope

Microsoft Teams has become a key communication tool for thousands of businesses worldwide. Its widespread use makes it a particularly attractive target for cybercriminal groups, who know that employees trust a video conference or call more than a simple email.

Several campaigns using a similar strategy have been reported recently, targeting organizations in the financial and healthcare sectors. In several cases, attackers were able to gain remote access to employee devices, move laterally around the corporate network, and ultimately steal sensitive information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: SkillCloak: Malicious AI Skills bypass scanners

Microsoft Teams: Fake IT support calls lead to EtherRAT distribution

New protection measures and what businesses should pay attention to

The increasing frequency of these attacks has led Microsoft to beef up Teams' security mechanisms. Newer features include more prominent warnings about external callers and conversations, as well as policies that restrict the action of suspicious third-party bots, automatically placing them on hold until approved by a meeting organizer.

However, technology alone is not enough. Employee education remains the most important defense against social engineering attacks. Businesses are urged to implement strict policies on remote access, verify every technical support request through internal processes, and remind users that no IT department will request remote control via an external call without warning. In an environment where cyber threats evolve daily, awareness and vigilance are the most effective line of defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS