Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors have devised a sophisticated scheme to trick employees into installing malware on their work computers, using Microsoft Teams voice calls as the entry point. By impersonating corporate IT support staff, attackers are gaining initial access to corporate networks, paving the way for further exploitation and data theft.

The campaign, uncovered by Palo Alto Networks’ Unit 42, combines phishing emails, Microsoft Teams voice calls, legitimate remote management tools, and a Node.js-based malware loader to compromise victims’ computers. The attack begins with a phishing email containing an “Employee Survey” lure and a malicious PDF attachment. Shortly after opening the document, the victim receives a Microsoft Teams voice call from an external account posing as a “System Administrator.” The caller’s unfamiliarity is indicated by the “External unfamiliar” label on the Teams session.

The attacker guides the victim through installing legitimate remote-access tools, such as HopToDesk and AnyDesk, ostensibly to provide support. Once remote access is established, the attacker downloads and executes a malicious MSI installer from camorreado.click. This malware loader acts as an intermediary, downloading a legitimate Node.js runtime, decrypting embedded payloads, and ultimately launching EtherRAT – a cross-platform remote access trojan written in Node.js.

EtherRAT grants attackers full control over compromised systems, allowing them to execute commands, manipulate files, steal data, and maintain persistence. What’s more concerning is that this malware uses Ethereum smart contracts to retrieve its active command-and-control (C2) server, making it harder for security teams to disrupt the attack chain.

This campaign follows a growing trend of attacks abusing Microsoft Teams to breach corporate networks. In March, a similar campaign targeted financial and healthcare organizations by flooding victims’ inboxes with spam and contacting them via Microsoft Teams. This latest scheme indicates that threat actors are continually adapting and refining their tactics, exploiting new vulnerabilities in the process.

Microsoft has been adding new protections to Teams in response to these attacks. The company recently introduced warnings that identify external callers and chats, as well as a new administrator policy that automatically places suspected third-party bots into the meeting lobby until organizers can manually approve their admission. While these measures are a step in the right direction, they underscore the need for organizations to remain vigilant.

To protect against these types of attacks, security teams must be proactive rather than reactive. This means testing every layer of defense before attackers do – including monitoring systems, intrusion detection systems, and endpoint protection software. By simulating breach and attack scenarios, security teams can identify weaknesses in their defenses and improve their response times. Ultimately, this requires a holistic approach to cybersecurity that combines technical measures with employee education and awareness training.


Source: Bleeping Computer — 2026-07-06