Fake Microsoft Teams IT Support Calls Used to Spread EtherRAT Malware

Cybersecurity researchers have uncovered a new attack campaign in which cybercriminals use fake Microsoft Teams support calls to infect company computers with a dangerous malware known as EtherRAT. The attackers pretend to be members of an organization’s IT department and convince employees to give them remote access to their devices.
The campaign was recently identified by Palo Alto Networks’ Unit 42 research team. According to the researchers, the attackers combine phishing emails, Microsoft Teams voice calls, legitimate remote access software, and a malware loader to gain full control of corporate systems.
The attack begins with a phishing email that appears to be harmless. The email usually contains an “Employee Survey” and includes a malicious PDF attachment. Once the employee opens the document, the next stage of the attack starts almost immediately.
Fake Microsoft Teams IT Support Calls Used to Spread EtherRAT Malware
Shortly after opening the file, the victim receives a voice call through Microsoft Teams. The caller claims to be a company system administrator or IT support representative. Since the call comes from an external Microsoft 365 account, Microsoft Teams displays an “External unfamiliar” warning. However, many users ignore this alert because the caller sounds professional and claims to be helping with a technical issue.
Researchers found that attackers used an external Microsoft account while pretending to work for the company’s IT department. During the call, they asked employees to share their screens and grant remote control through Microsoft Teams’ built-in screen-sharing feature.
Once the victim agrees, the attackers guide them through installing trusted remote access applications such as HopToDesk and AnyDesk. Because these are legitimate tools, employees often do not suspect anything unusual.
After securing remote access, the attackers download and install a malicious MSI file from a fake website. This installer acts as a malware loader. It downloads a legitimate Node.js runtime, decrypts hidden malicious files, and finally installs EtherRAT on the victim’s computer.
EtherRAT is a powerful remote access trojan built with Node.js. After installation, it allows attackers to run commands, manage files, steal sensitive information, and maintain long-term access to the infected system. One of its most advanced features is its ability to retrieve command-and-control server information through Ethereum smart contracts, making it more difficult for security teams to detect or shut down the malware.
Security researchers noted that EtherRAT has appeared in previous cyberattacks, including campaigns linked to the React2Shell vulnerability. Over time, more cybercriminal groups have adopted the malware because of its flexibility and advanced capabilities.
See Also: Microsoft Introduces Scout: A New Autonomous AI Assistant for Microsoft 365
During their investigation, Unit 42 researchers also discovered an open online directory containing several versions of the malware installer. The presence of multiple versions suggests that the attackers continue to improve and expand the campaign.
This is not the first time criminals have abused Microsoft Teams to target businesses. Earlier this year, similar attacks focused on financial and healthcare organizations. Attackers first overwhelmed employees with spam emails before contacting them through Microsoft Teams and pretending to be IT support. Those attacks eventually installed another malware called A0Backdoor.
In response to these growing threats, Microsoft has introduced several security improvements for Teams. The company now clearly labels external callers and chats to help users identify potential phishing or voice phishing attempts. Microsoft has also launched a new administrator policy that places suspicious third-party bots into a meeting lobby until organizers manually approve their entry.
Cybersecurity experts advise employees to remain cautious when receiving unexpected IT support calls, even if they appear to come through trusted communication platforms. Verifying the caller’s identity before granting remote access can help prevent serious security breaches and protect sensitive company data.
Mobile Phone Taxes Portal
Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.
Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).
Explore NowFollow us on Google News!