Microsoft Teams call installs EtherRAT malware
Attackers trick employees into answering a fake Microsoft Teams call from a fake IT admin, then install EtherRAT malware to take over their computer. The attack starts with a phishing email and a fake PDF file.
- Report priority
- High
- Targets
- Microsoft 365+1 more
How it works
A fake Microsoft Teams call from a spoofed IT admin account, triggered by opening a malicious PDF sent in a phishing email.
What to do
Check if you opened a PDF attachment from an unexpected email claiming to be an 'Employee Survey' or any other fake survey in the last few days.
Delete the email and the PDF immediately. Do not answer any unexpected Teams calls from unknown external accounts. Enable Microsoft Defender for Office 365 to block malicious attachments and calls.
Technical details
Affected software: Microsoft 365, EtherRAT
You get an email saying 'Employee Survey' with a fake PDF attachment. When you open it, a fake Microsoft Teams call pops up from a fake IT admin. You answer the call, and the attacker secretly installs EtherRAT malware on your computer. Now they can control your machine without you knowing.
A threat actor campaign abuses Microsoft Teams screen-sharing sessions to deploy EtherRAT, a Node.js-based remote access trojan (RAT). The attack begins with a phishing email containing a malicious PDF that triggers an unexpected Teams call from a compromised external account impersonating a "System Administrator." The attacker, using a domain mimicking a legitimate helpdesk, convinces the victim to enable screen sharing, then guides them through installing legitimate remote monitoring and management (RMM) tools, creating a plausible cover for the intrusion. Once remote access is established, the attacker deploys a malicious MSI installer that silently downloads Node.js and decrypts EtherRAT payloads.
The loader's use of trusted software components evades detection, allowing the RAT to persist across Windows, macOS, and Linux systems. EtherRAT grants attackers full control over compromised devices, enabling data theft, lateral movement, and undetected persistence.
References
- github.com · 2026-06-28-Fake-IT-support-abuses-Teams-to-deliver-EtherRAT.txt (main) Cyber Security News
- bleepingcomputer.com · fake-it-support-calls-on-microsoft-teams-push-etherrat-malware Cyber Security News
- any.run · threat-intelligence-feeds Cyber Security News
- bleepingcomputer.com · artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit BleepingComputer
- securityonline.info · artoken-phishing-platform-microsoft-365 SecurityOnline
- infosecurity-magazine.com · hackers-blockchain-japan-hotels Infosecurity Magazine
- blog.nns.ee · katana-badusb-fix NNS Blog
- neuracybintel.com · gentlekiller-exploits-vulnerable-drivers-to-dismantle-endpoint-protection-at-scale NeuraCybIntel
- welivesecurity.com · killing-me-gently-inside-gentlemens-edr-killer-framework NeuraCybIntel
- thehackernews.com · the-gentlemen-raas-uses-gentlekiller.html NeuraCybIntel
- helpnetsecurity.com · eset-gentlemen-edr-killers NeuraCybIntel
- eset.com · what-are-edr-killers NeuraCybIntel
- thehackernews.com · certcc-warns-of-hidden-admin-backdoor.html TheHackerNews
- neuracybintel.com · ai-brands-become-the-new-phishing-lure-as-threat-actors-exploit-chatgpt-copilot-claude-and-deepseek-hype NeuraCybIntel
- microsoft.com · ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering NeuraCybIntel
- microsoft.com · ai-as-tradecraft-how-threat-actors-operationalize-ai NeuraCybIntel
- itpro.com · hackers-are-capitalizing-on-ai-hype-to-ramp-up-social-engineering-attacks-and-theyre-using-big-brands-like-anthropic-openai-and-deepseek-as-bait-to-lure-victims NeuraCybIntel
- thehackernews.com · us-government-entity-paid-kairos-group.html TheHackerNews
- thehackernews.com · fortibleed-credential-theft-linked-to.html TheHackerNews
- securityonline.info · kairos-ransomware-data-extortion SecurityOnline
- thehackernews.com · new-java-based-quimarat-maas-built-to.html TheHackerNews