Fake IT support calls on Microsoft Teams push EtherRAT malware

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks.

The campaign, reported by Palo Alto Networks’ Unit 42, combines phishing emails, Microsoft Teams voice calls, legitimate remote management tools, and a Node.js-based malware loader to compromise victims’ computers.

According to a report by Unit 42 posted on GitHub, the attack begins with a phishing email containing an “Employee Survey” lure and a malicious PDF attachment.

Read more: bleepingcomputer.com