Microsoft Teams call installs EtherRAT malware

Published July 6, 2026

Attackers trick employees into answering a fake Microsoft Teams call from a fake IT admin, then install EtherRAT malware to take over their computer. The attack starts with a phishing email and a fake PDF file.

Report priority
High
Targets
Microsoft 365+1 more

How it works

A fake Microsoft Teams call from a spoofed IT admin account, triggered by opening a malicious PDF sent in a phishing email.

What to do

Check if you opened a PDF attachment from an unexpected email claiming to be an 'Employee Survey' or any other fake survey in the last few days.

Delete the email and the PDF immediately. Do not answer any unexpected Teams calls from unknown external accounts. Enable Microsoft Defender for Office 365 to block malicious attachments and calls.

Technical details

Affected software: Microsoft 365, EtherRAT

You get an email saying 'Employee Survey' with a fake PDF attachment. When you open it, a fake Microsoft Teams call pops up from a fake IT admin. You answer the call, and the attacker secretly installs EtherRAT malware on your computer. Now they can control your machine without you knowing.

A threat actor campaign abuses Microsoft Teams screen-sharing sessions to deploy EtherRAT, a Node.js-based remote access trojan (RAT). The attack begins with a phishing email containing a malicious PDF that triggers an unexpected Teams call from a compromised external account impersonating a "System Administrator." The attacker, using a domain mimicking a legitimate helpdesk, convinces the victim to enable screen sharing, then guides them through installing legitimate remote monitoring and management (RMM) tools, creating a plausible cover for the intrusion. Once remote access is established, the attacker deploys a malicious MSI installer that silently downloads Node.js and decrypts EtherRAT payloads.

The loader's use of trusted software components evades detection, allowing the RAT to persist across Windows, macOS, and Linux systems. EtherRAT grants attackers full control over compromised devices, enabling data theft, lateral movement, and undetected persistence.

References