Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How

    August 9, 2026

    These AI Barons Are Ready to Give Away Their Fortunes

    August 9, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 8)

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How
    • These AI Barons Are Ready to Give Away Their Fortunes
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    • How ideas of a vast censorship network moved from the online fringe to Trump policy
    • The Pivot From Tech Expert to Organizational Leader
    • Scientists Used AI to Create 16 New Viruses
    • The Download: a censorship conspiracy theory and the first virus created by AI
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Fake IT support calls on Microsoft Teams push EtherRAT malware
    Cybersecurity

    Fake IT support calls on Microsoft Teams push EtherRAT malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 7, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Microsoft Teams
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks.

    The campaign, reported by Palo Alto Networks’ Unit 42, combines phishing emails, Microsoft Teams voice calls, legitimate remote management tools, and a Node.js-based malware loader to compromise victims’ computers.

    According to a report by Unit 42 posted on GitHub, the attack begins with a phishing email containing an “Employee Survey” lure and a malicious PDF attachment.

    Shortly after opening the document, the victim receives a Microsoft Teams voice call from an external account impersonating a “System Administrator.”

    The researchers observed the Teams session displaying the “External unfamiliar” label, indicating the caller belonged to a different Microsoft 365 tenant than the recipient. Audit logs showed the attacker initiated the external chat using the account helpdesk@Progressive936.onmicrosoft[.]com while posing as IT support.

    After convincing the victim to grant remote control via Microsoft Teams’ built-in screen-sharing feature, the attacker guided them through installing legitimate remote-access tools, including HopToDesk and AnyDesk.

    After establishing remote access, they downloaded and executed a malicious MSI installer (v7.msi) from camorreado[.]click. The MSI acts as a malware loader, downloading a legitimate Node.js runtime, decrypting embedded payloads, and ultimately launching EtherRAT.

    EtherRAT is a cross-platform remote access trojan written in Node.js that gives attackers full control over compromised systems.

    The malware can execute commands, manipulate files, steal data, and maintain persistence, while using Ethereum smart contracts to retrieve its active command-and-control (C2) server, making it harder to disrupt.

    EtherRAT was previously used in state-sponsored attacks exploiting the React2Shell vulnerability and has since been adopted by numerous other threat actors.

    Unit 42 says they discovered an open directory on a distribution server containing multiple versions of the malware installers (v1 through v9), indicating the campaign is actively being developed.

    Teams attacks force Microsoft to add new protections

    The latest campaign follows a growing number of attacks abusing Microsoft Teams to breach corporate networks.

    In March, a campaign targeted financial and healthcare organizations by flooding victims’ inboxes with spam, then contacting them via Microsoft Teams, posing as company IT staff. Victims were tricked into launching Quick Assist sessions that ultimately led to the deployment of the newly documented A0Backdoor malware.

    A month later, Microsoft warned that attackers were increasingly abusing external Microsoft Teams to impersonate helpdesk personnel and convince employees to give them remote access to their devices. Once inside the network, the attackers performed reconnaissance, spread laterally to other devices, and ultimately stole data.

    To help defend against these attacks, Microsoft has been adding new protections to Teams.

    Earlier this year, the company added warnings that identify external callers and chats to protect against potential phishing/vishing attacks.

    Last week, Microsoft also introduced a new Teams administrator policy that automatically places suspected third-party bots into the meeting lobby until organizers can manually approve their admission.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Calls EtherRAT Fake malware Microsoft push support Teams
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How
    • These AI Barons Are Ready to Give Away Their Fortunes
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    • How ideas of a vast censorship network moved from the online fringe to Trump policy

    Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How

    August 9, 2026

    These AI Barons Are Ready to Give Away Their Fortunes

    August 9, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 8)

    August 8, 2026

    How to Disable Gemini in Gmail and Google Docs

    August 8, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.