Threat actors are leveraging Microsoft Teams voice calls to impersonate IT support staff and trick employees into installing the EtherRAT malware, according to research from Palo Alto Networks' Unit 42. This tactic grants attackers initial access to corporate networks. The operation combines phishing emails, Teams voice calls, legitimate remote management tools, and a custom malware loader to compromise victim systems.
The attack sequence begins with a phishing email containing a lure such as an "Employee Survey" and a malicious PDF attachment. Upon opening the document, the targeted employee receives a Microsoft Teams voice call. The caller impersonates a "System Administrator" and is identified as an external party, indicating they are from a different Microsoft 365 tenant. Audit logs revealed an attacker initiated a chat using an external account, helpdesk@Progressive936.onmicrosoft[.]com, while posing as IT support.
After convincing the victim to share their screen via Microsoft Teams, the attacker guides them through installing legitimate remote access tools like HopToDesk and AnyDesk. Once remote access is established, the attackers download and execute a malicious MSI installer from camorreado[.]click. This MSI file functions as a malware loader. It downloads a legitimate Node.js runtime, decrypts embedded malicious payloads, and ultimately deploys EtherRAT.
EtherRAT is a cross-platform remote access trojan developed in Node.js. It provides attackers with comprehensive control over compromised systems, enabling them to execute commands, manipulate files, exfiltrate data, and establish persistence. A notable feature of EtherRAT is its use of Ethereum smart contracts to retrieve its active command-and-control server information, which complicates efforts to disrupt its operations. This malware has previously been associated with state-sponsored attacks and has since been adopted by various other threat groups.
Unit 42 researchers discovered an open directory on a distribution server containing multiple versions of the malware installers, from v1 to v9. This suggests the ongoing development and active use of this campaign.
This latest campaign highlights a growing trend of attackers exploiting Microsoft Teams to breach corporate networks. In March, a similar campaign targeted financial and healthcare organizations by using spam emails followed by Teams calls from individuals impersonating IT staff. Victims in that instance were persuaded to launch Quick Assist sessions, which led to the deployment of the A0Backdoor malware.
In April, Microsoft issued a warning about attackers increasingly using external Microsoft Teams accounts to impersonate helpdesk personnel. These attackers would then convince employees to grant them remote access to their devices. Once inside a network, these threat actors would conduct reconnaissance, spread to other devices, and steal data.
Microsoft has been implementing new protections within Teams to counter these evolving threats. Earlier this year, the company introduced warnings to identify external callers and chats, aiming to protect users from potential phishing and vishing attacks. More recently, Microsoft introduced a new administrator policy for Teams that automatically places suspected third-party bots into the meeting lobby, requiring manual approval from organizers before they can join.






