Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Inside the Inference Hardware Revolution Of 2026

    September 15, 2026

    What must happen for AI’s trillion-dollar gamble to pay off

    September 15, 2026

    When AI agents cheated at math, other AI agents blew the whistle on them

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction
    • Donated livers can be made biologically younger
    • Responsible AI for Higher Education
    • The Real AI Disruption Isn’t the Technology. It’s the Company.
    • New York Seizes a Dozen Celebrity Deepfake Websites
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Fake IT support calls on Microsoft Teams push EtherRAT malware
    Cybersecurity

    Fake IT support calls on Microsoft Teams push EtherRAT malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 7, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Microsoft Teams
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks.

    The campaign, reported by Palo Alto Networks’ Unit 42, combines phishing emails, Microsoft Teams voice calls, legitimate remote management tools, and a Node.js-based malware loader to compromise victims’ computers.

    According to a report by Unit 42 posted on GitHub, the attack begins with a phishing email containing an “Employee Survey” lure and a malicious PDF attachment.

    Shortly after opening the document, the victim receives a Microsoft Teams voice call from an external account impersonating a “System Administrator.”

    The researchers observed the Teams session displaying the “External unfamiliar” label, indicating the caller belonged to a different Microsoft 365 tenant than the recipient. Audit logs showed the attacker initiated the external chat using the account helpdesk@Progressive936.onmicrosoft[.]com while posing as IT support.

    After convincing the victim to grant remote control via Microsoft Teams’ built-in screen-sharing feature, the attacker guided them through installing legitimate remote-access tools, including HopToDesk and AnyDesk.

    After establishing remote access, they downloaded and executed a malicious MSI installer (v7.msi) from camorreado[.]click. The MSI acts as a malware loader, downloading a legitimate Node.js runtime, decrypting embedded payloads, and ultimately launching EtherRAT.

    EtherRAT is a cross-platform remote access trojan written in Node.js that gives attackers full control over compromised systems.

    The malware can execute commands, manipulate files, steal data, and maintain persistence, while using Ethereum smart contracts to retrieve its active command-and-control (C2) server, making it harder to disrupt.

    EtherRAT was previously used in state-sponsored attacks exploiting the React2Shell vulnerability and has since been adopted by numerous other threat actors.

    Unit 42 says they discovered an open directory on a distribution server containing multiple versions of the malware installers (v1 through v9), indicating the campaign is actively being developed.

    Teams attacks force Microsoft to add new protections

    The latest campaign follows a growing number of attacks abusing Microsoft Teams to breach corporate networks.

    In March, a campaign targeted financial and healthcare organizations by flooding victims’ inboxes with spam, then contacting them via Microsoft Teams, posing as company IT staff. Victims were tricked into launching Quick Assist sessions that ultimately led to the deployment of the newly documented A0Backdoor malware.

    A month later, Microsoft warned that attackers were increasingly abusing external Microsoft Teams to impersonate helpdesk personnel and convince employees to give them remote access to their devices. Once inside the network, the attackers performed reconnaissance, spread laterally to other devices, and ultimately stole data.

    To help defend against these attacks, Microsoft has been adding new protections to Teams.

    Earlier this year, the company added warnings that identify external callers and chats to protect against potential phishing/vishing attacks.

    Last week, Microsoft also introduced a new Teams administrator policy that automatically places suspected third-party bots into the meeting lobby until organizers can manually approve their admission.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Calls EtherRAT Fake malware Microsoft push support Teams
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Inside Meta’s Push to Put Robots to Work in Data Centers

    August 28, 2026

    AI Agents Are Hacking Systems. Could That Push the US and China to Cooperate?

    August 27, 2026

    Support networks aim to help kids through the polycrisis

    August 21, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction
    • Donated livers can be made biologically younger

    Inside the Inference Hardware Revolution Of 2026

    September 15, 2026

    What must happen for AI’s trillion-dollar gamble to pay off

    September 15, 2026

    When AI agents cheated at math, other AI agents blew the whistle on them

    September 15, 2026

    ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.