Attackers use fake Microsoft Teams IT support calls to install EtherRAT on employee computers

Attackers are calling employees on Microsoft Teams while pretending to be corporate IT staff and tricking them into installing malware that gives remote control of their computers. According to Palo Alto Networks' Unit 42, the campaign starts with an 'Employee Survey' phishing email and PDF, then a Teams voice call from an external Microsoft 365 tenant, followed by abuse of Teams screen sharing and remote tools including HopToDesk and AnyDesk. The attackers then run a malicious MSI installer that fetches Node.js and launches EtherRAT, a cross-platform remote access trojan that can execute commands, steal data, persist, and use Ethereum smart contracts to locate command-and-control servers.
Why it matters: Organizations using Microsoft Teams are at risk of employees being talked into giving attackers direct access to their devices. Defenders should warn staff not to trust unsolicited Teams support calls, restrict external Teams communications and remote-control features where possible, and review logs for suspicious external tenants, remote tool installs, and the listed infrastructure.

Sources

Fake IT bods on Microsoft Teams coax workers into installing malware
2026.07.07 98% relevant
This is a direct report on the same campaign, adding details on the lure sequence (employee survey email followed by a cross-tenant Teams call), use of HopToDesk or AnyDesk, the EtherRAT MSI installer, Ethereum smart-contract command-and-control discovery, and a forensic indicator in Teams files named "CtrlVirtualCursorWin_*".
Fake IT support calls on Microsoft Teams push EtherRAT malware
Lawrence Abrams 2026.07.06 100% relevant
This article establishes a distinct Teams-based vishing and malware-delivery campaign centered on EtherRAT, with specific lures, attacker tenant details, tooling, and infection chain.
← Back to all stories