Cybersecurity Threat Actors Abusing Microsoft Teams to Spread Malware
Threat actors have been using a sophisticated tactic to trick employees into installing malware on their computers, exploiting a vulnerability in corporate networks. The attackers are impersonating IT support staff via Microsoft Teams voice calls, convincing victims to grant remote access and ultimately downloading the EtherRAT malware.
The campaign begins with a phishing email containing an “Employee Survey” lure and a malicious PDF attachment. Upon opening the document, the victim receives a Microsoft Teams voice call from an external account claiming to be a system administrator. The attackers use legitimate remote management tools like HopToDesk and AnyDesk to gain control of the victim’s computer.
Once inside, they download and execute a malicious MSI installer that acts as a malware loader, downloading a Node.js runtime and ultimately launching EtherRAT. This cross-platform remote access trojan gives attackers full control over compromised systems, allowing them to execute commands, steal data, and maintain persistence.
The campaign is particularly concerning because it demonstrates the growing trend of threat actors abusing Microsoft Teams to breach corporate networks. In recent months, similar attacks have been reported, with attackers using external Microsoft Teams accounts to impersonate helpdesk personnel and convince employees to grant remote access.
Microsoft has taken steps to address these threats by adding new protections to Teams, including warnings that identify external callers and chats, as well as a new policy that automatically places suspected third-party bots into the meeting lobby until organizers can manually approve their admission.
To protect against these attacks, organizations should be vigilant about testing every layer of their defenses. Security teams are often aware of only 14% of successful attacks, with the remaining threats moving through the environment undetected. Regular breach and attack simulation tests can help identify weaknesses in SIEM and EDR rules, ensuring that security systems are effective in detecting and preventing these types of attacks.
Ultimately, this campaign highlights the importance of being cautious when receiving unsolicited calls or messages claiming to be from IT support staff. Employees should never grant remote access without verifying the identity of the caller, and organizations should remain vigilant about testing their defenses against emerging threats.
Source: Bleeping Computer — 2026-07-06